Skip to content
The Injection_
LIVE
LIVElast sweep UTCnext in--:--:--

[ RSS ][ JSON ][ llms.txt ]

Claude Code: symlink race allowed writes outside the project

Claude Code checked the path once and resolved it again at write time, so a well-timed symlink swap escaped the project folder.

· Anthropic · Research by c_h4ck_0 (HackerOne)

CVE-2026-103435
MEDVulnerability

CVE-2026-103435 is a time-of-check to time-of-use race in Claude Code before 2.1.129. A user who can write to a shared workspace could swap a file for a symlink and make Claude Code write outside the project.

01What happened

Anthropic published advisory GHSA-5j29-h97v-84ch on October 5, 2026 for a file write flaw in Claude Code. The reporter c_h4ck_0 disclosed it through HackerOne.

02How it works

Claude Code checked that a target path was inside the project directory during its permission check, then resolved the path again at write time without repeating the check. An attacker with write access to the same workspace can replace a project file with a symlink at the right moment, so the edit lands outside the project, for example in a shell config file. The attacker has to win the race.

03Who is affected

Users of @anthropic-ai/claude-code before 2.1.129, mainly in workspaces that other, less trusted users can write to. Auto-update already delivers the fix.

04What to do

Confirm Claude Code is on 2.1.129 or later, and avoid running it in directories that less trusted users can modify.

Sources 2 links, all fetched

  1. 1github.comAnthropic Advisory
  2. 2github.comAll Anthropic Advisories