Symbolic Link Vulnerability in Claude Code by Anthropic
CVE-2026-25724
What is CVE-2026-25724?
Prior to version 2.1.7, Claude Code, an agentic coding tool developed by Anthropic, exhibited a flaw in enforcing security rules defined in settings.json. Specifically, if a user set access restrictions on certain files, Claude Code could still bypass these restrictions by exploiting symbolic links. This vulnerability allowed unauthorized access to sensitive files, even if explicit deny rules were in place. The issue has been resolved in the latest version, ensuring that deny rules are correctly enforced when accessing files via symbolic links.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
claude-code < 2.1.7
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
