Users on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to the latest version.
Thank you to hackerone.com/c_h4ck_0 for reporting this issue.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 07 Oct 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 07 Oct 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Claude Code validated that a target file path resided within the project working directory at permission-check time, but re-resolved the path at write time without repeating that validation. This time-of-check to time-of-use (TOCTOU) gap allowed an attacker who could write to the workspace to atomically replace a project file with a symlink, causing Claude Code to follow the symlink and write its output to an arbitrary file outside the project sandbox. Exploitation required the ability to win a race condition against the write operation and write access to the shared workspace, enabling a lower-privileged attacker to redirect benign edits to sensitive files (e.g., shell configuration) in a higher-privileged session. Users on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to the latest version. Thank you to hackerone.com/c_h4ck_0 for reporting this issue. | |
| Title | Arbitrary File Write via Write-Time Symlink Following (TOCTOU) in Claude Code | |
| Weaknesses | CWE-22 CWE-367 CWE-61 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Anthropic
Published:
Updated: 2026-10-07T14:39:13.225Z
Reserved: 2026-09-30T15:35:18.777Z
Link: CVE-2026-103435
Updated: 2026-10-07T14:39:09.178Z
Status : Awaiting Analysis
Published: 2026-10-07T13:17:16.690
Modified: 2026-10-07T15:16:57.037
Link: CVE-2026-103435
No data.
OpenCVE Enrichment
No data.