high Cve 2026 103435 · AI Security

Claude Code symlink race lets file writes escape the project directory (CVE-2026-103435)

Data graphic: Claude Code symlink race CVE-2026-103435 rated CVSS v4.0 7.7 High; affected before 2.1.129, fixed in 2.1.129.
OP

AI security researcher · Published Oct 10, 2026, 6:57 AM EDT

CVE-2026-103435 (CVSS v4.0 7.7) is a symlink race in Claude Code before 2.1.129, fixed in May 2026, that can redirect a write outside the project. No exploitation reported.

Claude Code versions before 2.1.129 can be made to write outside the project directory they are working in. CVE-2026-103435 is a time-of-check to time-of-use (TOCTOU) flaw in the way the tool handles file writes. It is rated 7.7 (High) under CVSS v4.0. It is fixed in 2.1.129, which npm published on 5 May 2026, five months before the advisory appeared, so only installs that have not updated since early May are exposed. The advisory does not report exploitation, and the CISA coordinator entry in NVD records exploitation as "None".

What happened

Anthropic's GitHub advisory GHSA-5j29-h97v-84ch describes the bug this way: Claude Code checked that a target file path was inside the project working directory when it checked permissions, but resolved the path again at write time without repeating that check. Someone who could write to the workspace could swap a project file for a symlink in that gap. Claude Code would then follow the symlink and write its output to a file outside the project sandbox.

The affected package is the npm package @anthropic-ai/claude-code, in all versions below 2.1.129. The advisory credits the researcher c_h4ck_0, whose HackerOne profile is linked in the advisory. Version 2.1.129 reached the npm registry on 5 May 2026; the current release is 2.1.296 as of 10 October. The GitHub advisory was published on 5 October, and the NVD record followed on 7 October. At the time of writing NVD lists it as Awaiting Analysis.

Timeline

  • 5 May 2026: 2.1.129 published to npm (per the npm registry)
  • 5 October 2026: GitHub advisory GHSA-5j29-h97v-84ch published
  • 7 October 2026: NVD record published

Why it matters

The people most exposed are those who run Claude Code in a workspace that someone else can also write to. Examples are shared build hosts, shared development servers and multi-user checkouts. The advisory says a lower-privileged user could redirect edits that look harmless into sensitive files, with shell configuration given as an example, inside a session running with higher privileges. Our inference: a changed shell configuration file would run the next time that account opens a shell. (We covered a similar file-based flaw in the Claude Desktop Cowork folder bug, and the unsandboxed Claude Code mods run with the same permissions.)

Because the fix is five months old, the realistic exposure is stale installs: pinned container images, CI images, offline machines and shared servers where nobody updates. Machines on standard auto-update are almost certainly past 2.1.129 already.

A developer on a personal machine with no other writers in the workspace has much less exposure, because the attack needs workspace write access.

Technical details

Diagram: permission check, symlink swap, write re-resolved, write lands outside the project directory; patched in 2.1.129.

How the check-then-write race redirects a write (GHSA-5j29-h97v-84ch).

  • Class: TOCTOU race. The advisory lists CWE-22 (path traversal), CWE-61 (symlink following) and CWE-367 (TOCTOU race condition).
  • Mechanism: the permission check covers the path as it resolved at check time. The write re-resolves the path, and the second resolution is not validated. Replacing a project file with a symlink in between changes where the write goes.
  • Preconditions: write access to the workspace, and winning the race against the write.
  • Score: CVSS 7.7 High, vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. The score comes from the GitHub CNA. NVD has not added its own score.
  • Exploitation signals: the SSVC entry from the CISA coordinator reads Exploitation: None, Automatable: No, Technical Impact: Total. No in-the-wild exploitation is reported in the sources we read.

The vector lists network attack vector and no privileges required. That sits uneasily with the advisory text, which requires workspace write access. We report the scoring as published and do not reinterpret it.

What defenders should do

  1. Check your version. Confirm that every install is 2.1.129 or later (the current release is 2.1.296), for example with claude --version (the command is not from the advisory). Developer laptops, shared servers, containers and CI images can each carry a separate install.
  2. Update. The advisory says users on standard auto-update have already received the fix. Manual or pinned installs, including pinned container images, need an explicit update.
  3. Reduce who can write to the workspace. The advisory documents no workarounds. Until installs are updated, avoid running the tool in directories that other users or untrusted processes can modify.
  4. Review sensitive files such as shell startup files on shared hosts where an older version ran. Check for unexpected symlinks and unexplained edits.

What is still unclear

  • The advisory gives no detail on how reliably the race can be won, and no proof of concept is cited.
  • NVD analysis is pending, so the score and affected-configuration data could change.
  • The advisory does not say whether it covers other write paths or tools beyond file edits.

Sources

Keep reading

All latest →
  1. highAI SecurityLMCache CVE-2026-105192: Unauthenticated Pickle RCE in Multiprocess Mode, With No Fixed Release Yet6 min
  2. highAI SecurityFake ChatGPT, Gemini, Claude and Muse ad portals use a fake browser window to steal ad-account logins7 min
  3. watchAI SecurityOpenAI Notified 100+ Organizations About Model Activity: A Notice Is Not a Compromise8 min
  4. highAI SecurityMCP TypeScript SDK Lets a Malicious Server Pull OAuth Secrets From Clients (CVE-2026-104850)4 min
  5. elevatedAI SecurityMistral Large 4 preview ships a reduced-moderation cyber tier, and Artificial Analysis lists its 82% as the top score6 min
  6. watchAI SecurityNextChat proxy fallback lets unauthenticated callers make the server fetch any URL (CVE-2026-105238)7 min