Anthropic published the Claude Code symlink-write CVE; the patch shipped in May 2026

CVE-2026-103435 affects Claude Code before 2.1.129; version 2.1.129 fixed the write race on 2026-05-06, before disclosure on 2026-10-05.

Claude Code versions before 2.1.129 could follow a symlink swapped after permission checking and write outside the project. Claude Code 2.1.129 fixed that write-time TOCTOU issue on 2026-05-06; GitHub published GHSA-5j29-h97v-84ch and CVE-2026-103435 on 2026-10-05. On 2026-10-06, npm listed 2.1.290 as the latest package version.

Key facts about Claude Code CVE-2026-103435

  • GitHub published GHSA-5j29-h97v-84ch and CVE-2026-103435 on 2026-10-05. The advisory publisher is ddworken, and the affected package is @anthropic-ai/claude-code.
  • The advisory marks versions < 2.1.129 as affected and 2.1.129 as patched.
  • The advisory rates the issue High with a CVSS v4 score of 7.7. It lists CWE-22, CWE-61 and CWE-367.
  • GitHub dates release v2.1.129 to 2026-05-06. npm published package 2.1.129 at 2026-05-05T18:22:55.515Z.
  • The advisory says standard Claude Code auto-update users already received the fix. Manual installations should be updated.
  • Claude Code 2.1.280, published on npm on 2026-09-22, added later permission hardening for writes through symlinked paths.
  • Claude Code 2.1.290, published on npm on 2026-10-05, added separate protections for image reads and @ mentions whose links changed during a read.

How Claude Code CVE-2026-103435 worked

Claude Code checked that a write path stayed inside the project when it asked for permission. In versions before 2.1.129, it resolved the path again when it wrote the file without repeating that containment check. That gap gave an attacker with write access to the shared workspace a race window.

The path could change like this:

permission check:  ./src/config.ts  -> project file
symlink swap:     ./src/config.ts  -> ~/.bashrc
write operation:  Claude Code follows the new link

The attacker had to replace the project file with a symlink at the right moment and win the race against the write. The advisory describes the result as an arbitrary write outside the project sandbox, with a lower-privileged attacker able to redirect an edit in a higher-privileged Claude Code session.

How Claude Code versions 2.1.129 and 2.1.280 handle symlinked writes

Version 2.1.129 is the patched version named by the advisory. Claude Code's permission and error documentation describes the checks that protect the write path:

  • If the requested file is itself a symlink, the Edit and Write tools refuse it and direct Claude to the link's target path.
  • If a symlink along the path changes after permission checking, Claude Code refuses the operation when it opens the approved file.
  • Allow rules must match both the requested path and the resolved target. Deny rules apply when either path matches.
  • Claude Code 2.1.280 added a later approval change. Its prompt names where a symlinked write lands, and acceptEdits, allow rules and auto mode no longer approve a write that resolves outside the project.

This protection arrived in stages. Before version 2.1.251, Claude Code rechecked path resolution for file writes but not for reads or searches. The original CVE is the write-side issue disclosed on 2026-10-05; versions 2.1.251, 2.1.280 and 2.1.290 extend the same path-safety model to more operations and approval modes.

The 2.1.290 changelog records two read-side fixes on 2026-10-05. An image read on macOS and Windows could return a file outside the approved location if a link changed during the read. An @ mention under the read block or --restricted could also read outside the working directories through a link changed mid-read.

That is different from CVE-2026-103435:

Property

CVE-2026-103435

Claude Code 2.1.290 changelog fixes

Operation

File write and edit

Image read and @-mention read

Failure

A write followed a swapped symlink

A read returned an outside file after a link changed

Patched version

2.1.129

2.1.290

First published

2026-05-05 on npm

2026-10-05 on npm

The practical answer is simple. A Claude Code installation below 2.1.129 is in the advisory's affected range. On 2026-10-06, the npm registry listed 2.1.290 as latest, so manual installations should be updated to that version or later.

Sources for Claude Code CVE-2026-103435

Last verified: 2026-10-06.

Spotted an outdated or wrong claim? Agents can report it with evidence throughPOST /api/feedback; an editor checks every report. See llms.txt for the agent API.