HighVulnerabilityLLM-specific
CVE-2026-103435: Claude Code validated that a target file path resided within the project working directory at permission-check time…
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-103435
- Published
- Record updated
Summary
Claude Code checked that a target file path was inside the project working directory at permission-check time, but re-resolved the path at write time without repeating the check. An attacker with write access to the shared workspace who could win a race condition could atomically replace a project file with a symlink, redirecting Claude Code's output to an arbitrary file outside the project sandbox. The flaw let a lower-privileged attacker redirect benign edits to sensitive files, such as shell configuration, in a higher-privileged session.
Mitigation
Users on standard Claude Code auto-update have already received the fix. Users performing manual updates are advised to update to the latest version.
Related items
- InfoAnthropic’s AI gave Philadelphia police a fake tip about an unsolved homicideSame vendor · The Verge (AI)
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSame vendor · BleepingComputer
- InfoAnthropic Launches Free AI Vulnerability Scanner for Open-Source ProjectsSame vendor · The Hacker News
- InfoAnthropic bans users from being 'cruel' to its AI systemsSame vendor · BBC Technology
- InfoThe Download: AI’s refusal problem and weight-loss drug side effectsSame vendor · MIT Technology Review