Description
Claude Code validated that a target file path resided within the project working directory at permission-check time, but re-resolved the path at write time without repeating that validation. This time-of-check to time-of-use (TOCTOU) gap allowed an attacker who could write to the workspace to atomically replace a project file with a symlink, causing Claude Code to follow the symlink and write its output to an arbitrary file outside the project sandbox. Exploitation required the ability to win a race condition against the write operation and write access to the shared workspace, enabling a lower-privileged attacker to redirect benign edits to sensitive files (e.g., shell configuration) in a higher-privileged session.

Users on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to the latest version.

Thank you to hackerone.com/c_h4ck_0 for reporting this issue.
Published: 2026-10-07
Score: 7.7 High
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Update Now
AI Analysis

Impact

Claude Code performed a path validation check when verifying that the target file lay inside the project working directory, but omitted the same check when the file was actually written. The TOCTOU gap allows an attacker with write access to replace a legitimate project file with a symlink pointing outside the sandbox. When the tool writes its output it follows the symlink and overwrites the arbitrary file, enabling a lower‑privileged user to redirect benign edits to sensitive files such as shell configuration in a higher‑privileged session.

Affected Systems

Anthropic’s Claude Code service, affecting any deployment that has not yet incorporated the latest auto‑update fix. Vulnerable versions include all releases prior to the public patch supplied by Anthropic. Users who manually manage updates should verify that they have migrated to the newest version.

Risk and Exploitability

The CVSS score of 7.7 indicates high severity. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog. The exploit requires the attacker to have write access to the shared workspace, to race the validation‑write window, and to replace a legitimate project file with a symlink pointing outside the sandbox. If achieved, a lower‑privileged user could redirect edit operations to arbitrary files, potentially altering critical configuration files such as shell profiles. The lack of publicly available exploits suggests that widespread exploitation has not yet been observed, but the vulnerability still presents a significant risk to systems that permit write access to the workspace.

Generated by OpenCVE AI on October 7, 2026 at 15:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Enable automatic upstream updates to ensure the fix is applied without manual intervention.
  • For systems that perform manual updates, download and install the latest release from the Anthropic repository immediately.
  • Restrict write permissions on the workspace directories to mitigate the TOCTOU race condition, allowing only trusted users to modify files.

Generated by OpenCVE AI on October 7, 2026 at 15:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 13:00:00 +0000

Type Values Removed Values Added
Description Claude Code validated that a target file path resided within the project working directory at permission-check time, but re-resolved the path at write time without repeating that validation. This time-of-check to time-of-use (TOCTOU) gap allowed an attacker who could write to the workspace to atomically replace a project file with a symlink, causing Claude Code to follow the symlink and write its output to an arbitrary file outside the project sandbox. Exploitation required the ability to win a race condition against the write operation and write access to the shared workspace, enabling a lower-privileged attacker to redirect benign edits to sensitive files (e.g., shell configuration) in a higher-privileged session. Users on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to the latest version. Thank you to hackerone.com/c_h4ck_0 for reporting this issue.
Title Arbitrary File Write via Write-Time Symlink Following (TOCTOU) in Claude Code
Weaknesses CWE-22
CWE-367
CWE-61
References
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Anthropic

Published:

Updated: 2026-10-07T14:39:13.225Z

Reserved: 2026-09-30T15:35:18.777Z

Link: CVE-2026-103435

cve-icon Vulnrichment

Updated: 2026-10-07T14:39:09.178Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-07T13:17:16.690

Modified: 2026-10-07T15:16:57.037

Link: CVE-2026-103435

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T15:15:18Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition

  • CWE-61

    UNIX Symbolic Link (Symlink) Following