Sandbox Escape Vulnerability in Claude Code by Anthropics
CVE-2026-39861
What is CVE-2026-39861?
Prior to version 2.1.64, Claude Code's sandbox allowed processes to create symlinks to locations outside the designated workspace. When write operations were performed through these symlinks, unsandboxed processes could inadvertently access and modify files outside the intended area in the system. This vulnerability potentially leads to unauthorized code execution beyond the safety of the sandbox. The exploitation of this flaw requires an attacker to introduce untrusted content into Claude Code, which would trigger the execution of sandboxed commands via prompt injection. Users using standard auto-update should already be protected with the latest version. Those managing updates manually need to upgrade to version 2.1.64 or later to ensure their systems are secure.
Affected Version(s)
claude-code < 2.1.64
