Impact
Claude Code performed a path validation check when verifying that the target file lay inside the project working directory, but omitted the same check when the file was actually written. The TOCTOU gap allows an attacker with write access to replace a legitimate project file with a symlink pointing outside the sandbox. When the tool writes its output it follows the symlink and overwrites the arbitrary file, enabling a lower‑privileged user to redirect benign edits to sensitive files such as shell configuration in a higher‑privileged session.
Affected Systems
Anthropic’s Claude Code service, affecting any deployment that has not yet incorporated the latest auto‑update fix. Vulnerable versions include all releases prior to the public patch supplied by Anthropic. Users who manually manage updates should verify that they have migrated to the newest version.
Risk and Exploitability
The CVSS score of 7.7 indicates high severity. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog. The exploit requires the attacker to have write access to the shared workspace, to race the validation‑write window, and to replace a legitimate project file with a symlink pointing outside the sandbox. If achieved, a lower‑privileged user could redirect edit operations to arbitrary files, potentially altering critical configuration files such as shell profiles. The lack of publicly available exploits suggests that widespread exploitation has not yet been observed, but the vulnerability still presents a significant risk to systems that permit write access to the workspace.
OpenCVE Enrichment