Symbolic Link Vulnerability in Claude Code by Anthropic
CVE-2026-25724

2.3LOW

Key Information:

Vendor

Anthropics

Vendor
CVE Published:
6 February 2026

What is CVE-2026-25724?

Prior to version 2.1.7, Claude Code, an agentic coding tool developed by Anthropic, exhibited a flaw in enforcing security rules defined in settings.json. Specifically, if a user set access restrictions on certain files, Claude Code could still bypass these restrictions by exploiting symbolic links. This vulnerability allowed unauthorized access to sensitive files, even if explicit deny rules were in place. The issue has been resolved in the latest version, ensuring that deny rules are correctly enforced when accessing files via symbolic links.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

claude-code < 2.1.7

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.