CVE-2026-103435
Awaiting Analysis Awaiting Analysis - Queue

Time-of-Check to Time-of-Use Path Traversal in Claude Code

Vulnerability report for CVE-2026-103435, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: 98a01053-8a31-4f6d-9aa9-252be161adc6

Description

Claude Code validated that a target file path resided within the project working directory at permission-check time, but re-resolved the path at write time without repeating that validation. This time-of-check to time-of-use (TOCTOU) gap allowed an attacker who could write to the workspace to atomically replace a project file with a symlink, causing Claude Code to follow the symlink and write its output to an arbitrary file outside the project sandbox. Exploitation required the ability to win a race condition against the write operation and write access to the shared workspace, enabling a lower-privileged attacker to redirect benign edits to sensitive files (e.g., shell configuration) in a higher-privileged session. Users on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to the latest version. Thank you to hackerone.com/c_h4ck_0 for reporting this issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Anthropic @anthropic-ai/claude-code 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CWE-367 The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.
CWE-61 The product, when opening a file or directory, does not sufficiently account for when the file is a symbolic link that resolves to a target outside of the intended control sphere. This could allow an attacker to cause the product to operate on unauthorized files.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a time-of-check to time-of-use (TOCTOU) race condition vulnerability in Claude Code. The software checks if a file path is within the project directory before writing, but later re-resolves the path without rechecking. An attacker can replace a file with a symlink during this gap, causing Claude Code to write output to an arbitrary file outside the sandbox.

Detection Guidance

This vulnerability is specific to the @anthropic-ai/claude-code npm package versions prior to 2.1.129. To detect it, check the installed version of the package using the command: npm list @anthropic-ai/claude-code. If the version is below 2.1.129, the system is vulnerable.

Impact Analysis

An attacker with write access to the workspace could redirect edits to sensitive files like shell configurations in higher-privileged sessions. This could lead to arbitrary file writes outside the project directory, potentially compromising system integrity or confidentiality.

Compliance Impact

This vulnerability could lead to unauthorized file access or modification, potentially violating data integrity and confidentiality requirements in GDPR and HIPAA. Unauthorized writes to sensitive files may result in compliance breaches.

Mitigation Strategies

Immediately update the @anthropic-ai/claude-code package to version 2.1.129 or later using the command: npm install @anthropic-ai/claude-code@latest. If auto-updates are enabled, ensure they are functioning properly. For manual updates, verify the latest version is installed.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103435. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart