PT-2026-6765 · Anthropic · Claude-Code
Ofirh
·
Published
2026-02-06
·
Updated
2026-05-21
·
CVE-2026-25724
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Claude Code versions prior to 2.1.7
Description
Claude Code, an agentic coding tool, did not properly enforce deny rules defined in the
settings.json file when handling symbolic links. Specifically, if access to a file (like /etc/passwd) was explicitly denied, but Claude Code had access to a symbolic link pointing to that file, the restricted file could be read through the symlink, bypassing the deny rule enforcement.Recommendations
Update to version 2.1.7 or later.
Exploit
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Claude-Code