# Claude Code: symlink race allowed writes outside the project

> Claude Code checked the path once and resolved it again at write time, so a well-timed symlink swap escaped the project folder.

- **Severity:** Medium: Real and reproducible, but needs unusual setup, user help or a narrow audience. Plan a fix.
- **Category:** Vulnerability
- **Published by:** Anthropic
- **Disclosed:** 2026-10-05
- **CVE:** CVE-2026-103435
- **CVSS:** 7.7
- **Affects:** Claude Code
- **Research by:** c_h4ck_0 (HackerOne)
- **Primary source:** https://github.com/anthropics/claude-code/security/advisories/GHSA-5j29-h97v-84ch
- **Page:** https://theinjection.dev/items/claude-code-symlink-toctou-file-write/

CVE-2026-103435 is a time-of-check to time-of-use race in Claude Code before 2.1.129. A user who can write to a shared workspace could swap a file for a symlink and make Claude Code write outside the project.

## What happened

Anthropic published advisory GHSA-5j29-h97v-84ch on October 5, 2026 for a file write flaw in Claude Code. The reporter c_h4ck_0 disclosed it through HackerOne.

## How it works

Claude Code checked that a target path was inside the project directory during its permission check, then resolved the path again at write time without repeating the check. An attacker with write access to the same workspace can replace a project file with a symlink at the right moment, so the edit lands outside the project, for example in a shell config file. The attacker has to win the race.

## Who is affected

Users of @anthropic-ai/claude-code before 2.1.129, mainly in workspaces that other, less trusted users can write to. Auto-update already delivers the fix.

## What to do

Confirm Claude Code is on 2.1.129 or later, and avoid running it in directories that less trusted users can modify.

## Sources

1. [Anthropic Advisory](https://github.com/anthropics/claude-code/security/advisories/GHSA-5j29-h97v-84ch)
2. [All Anthropic Advisories](https://github.com/anthropics/claude-code/security/advisories)
