CVE-2026-103435 (CVSS v4.0 7.7) is a symlink race in Claude Code before 2.1.129, fixed in May 2026, that can redirect a write outside the project. No exploitation reported.
Claude Code versions before 2.1.129 can be made to write outside the project directory they are working in. CVE-2026-103435 is a time-of-check to time-of-use (TOCTOU) flaw in the way the tool handles file writes. It is rated 7.7 (High) under CVSS v4.0. It is fixed in 2.1.129, which npm published on 5 May 2026, five months before the advisory appeared, so only installs that have not updated since early May are exposed. The advisory does not report exploitation, and the CISA coordinator entry in NVD records exploitation as "None".
What happened
Anthropic's GitHub advisory GHSA-5j29-h97v-84ch describes the bug this way: Claude Code checked that a target file path was inside the project working directory when it checked permissions, but resolved the path again at write time without repeating that check. Someone who could write to the workspace could swap a project file for a symlink in that gap. Claude Code would then follow the symlink and write its output to a file outside the project sandbox.
The affected package is the npm package @anthropic-ai/claude-code, in all versions below 2.1.129. The advisory credits the researcher c_h4ck_0, whose HackerOne profile is linked in the advisory. Version 2.1.129 reached the npm registry on 5 May 2026; the current release is 2.1.296 as of 10 October. The GitHub advisory was published on 5 October, and the NVD record followed on 7 October. At the time of writing NVD lists it as Awaiting Analysis.
Timeline
- 5 May 2026: 2.1.129 published to npm (per the npm registry)
- 5 October 2026: GitHub advisory GHSA-5j29-h97v-84ch published
- 7 October 2026: NVD record published
Why it matters
The people most exposed are those who run Claude Code in a workspace that someone else can also write to. Examples are shared build hosts, shared development servers and multi-user checkouts. The advisory says a lower-privileged user could redirect edits that look harmless into sensitive files, with shell configuration given as an example, inside a session running with higher privileges. Our inference: a changed shell configuration file would run the next time that account opens a shell. (We covered a similar file-based flaw in the Claude Desktop Cowork folder bug, and the unsandboxed Claude Code mods run with the same permissions.)
Because the fix is five months old, the realistic exposure is stale installs: pinned container images, CI images, offline machines and shared servers where nobody updates. Machines on standard auto-update are almost certainly past 2.1.129 already.
A developer on a personal machine with no other writers in the workspace has much less exposure, because the attack needs workspace write access.
Technical details
How the check-then-write race redirects a write (GHSA-5j29-h97v-84ch).
- Class: TOCTOU race. The advisory lists CWE-22 (path traversal), CWE-61 (symlink following) and CWE-367 (TOCTOU race condition).
- Mechanism: the permission check covers the path as it resolved at check time. The write re-resolves the path, and the second resolution is not validated. Replacing a project file with a symlink in between changes where the write goes.
- Preconditions: write access to the workspace, and winning the race against the write.
- Score: CVSS 7.7 High, vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. The score comes from the GitHub CNA. NVD has not added its own score. - Exploitation signals: the SSVC entry from the CISA coordinator reads Exploitation: None, Automatable: No, Technical Impact: Total. No in-the-wild exploitation is reported in the sources we read.
The vector lists network attack vector and no privileges required. That sits uneasily with the advisory text, which requires workspace write access. We report the scoring as published and do not reinterpret it.
What defenders should do
- Check your version. Confirm that every install is 2.1.129 or later (the current release is 2.1.296), for example with
claude --version(the command is not from the advisory). Developer laptops, shared servers, containers and CI images can each carry a separate install. - Update. The advisory says users on standard auto-update have already received the fix. Manual or pinned installs, including pinned container images, need an explicit update.
- Reduce who can write to the workspace. The advisory documents no workarounds. Until installs are updated, avoid running the tool in directories that other users or untrusted processes can modify.
- Review sensitive files such as shell startup files on shared hosts where an older version ran. Check for unexpected symlinks and unexplained edits.
What is still unclear
- The advisory gives no detail on how reliably the race can be won, and no proof of concept is cited.
- NVD analysis is pending, so the score and affected-configuration data could change.
- The advisory does not say whether it covers other write paths or tools beyond file edits.