Sandbox Escape Vulnerability in Claude Code by Anthropics
CVE-2026-39861

7.7HIGH

Key Information:

Vendor

Anthropics

Vendor
CVE Published:
21 April 2026

What is CVE-2026-39861?

Prior to version 2.1.64, Claude Code's sandbox allowed processes to create symlinks to locations outside the designated workspace. When write operations were performed through these symlinks, unsandboxed processes could inadvertently access and modify files outside the intended area in the system. This vulnerability potentially leads to unauthorized code execution beyond the safety of the sandbox. The exploitation of this flaw requires an attacker to introduce untrusted content into Claude Code, which would trigger the execution of sandboxed commands via prompt injection. Users using standard auto-update should already be protected with the latest version. Those managing updates manually need to upgrade to version 2.1.64 or later to ensure their systems are secure.

Affected Version(s)

claude-code < 2.1.64

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.