CVE-2026-103435

Source
https://cve.org/CVERecord?id=CVE-2026-103435
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-103435.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-103435
Aliases
  • GHSA-5j29-h97v-84ch
Published
2026-10-07T12:50:02Z
Modified
2026-10-08T02:49:15Z
Severity
  • 7.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Arbitrary File Write via Write-Time Symlink Following (TOCTOU) in Claude Code
Details

Claude Code validated that a target file path resided within the project working directory at permission-check time, but re-resolved the path at write time without repeating that validation. This time-of-check to time-of-use (TOCTOU) gap allowed an attacker who could write to the workspace to atomically replace a project file with a symlink, causing Claude Code to follow the symlink and write its output to an arbitrary file outside the project sandbox. Exploitation required the ability to win a race condition against the write operation and write access to the shared workspace, enabling a lower-privileged attacker to redirect benign edits to sensitive files (e.g., shell configuration) in a higher-privileged session.

Users on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to the latest version.

Thank you to hackerone.com/c_h4ck_0 for reporting this issue.

Database specific
{
    "cna_assigner": "Anthropic",
    "cwe_ids": [
        "CWE-22",
        "CWE-367",
        "CWE-61"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-103435.json"
}
References

Affected packages

Git / github.com/anthropics/claude-code

Affected ranges

Type
GIT
Repo
https://github.com/anthropics/claude-code
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.1.129"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v2.*
v2.0.73
v2.0.74
v2.0.76
v2.1.0
v2.1.1
v2.1.100
v2.1.101
v2.1.104
v2.1.105
v2.1.107
v2.1.108
v2.1.109
v2.1.11
v2.1.110
v2.1.111
v2.1.112
v2.1.113
v2.1.114
v2.1.116
v2.1.117
v2.1.118
v2.1.119
v2.1.12
v2.1.120
v2.1.121
v2.1.122
v2.1.123
v2.1.126
v2.1.128
v2.1.14
v2.1.15
v2.1.16
v2.1.17
v2.1.19
v2.1.2
v2.1.20
v2.1.21
v2.1.22
v2.1.23
v2.1.25
v2.1.27
v2.1.29
v2.1.3
v2.1.30
v2.1.31
v2.1.32
v2.1.33
v2.1.34
v2.1.36
v2.1.37
v2.1.38
v2.1.39
v2.1.4
v2.1.41
v2.1.42
v2.1.44
v2.1.45
v2.1.47
v2.1.49
v2.1.5
v2.1.50
v2.1.51
v2.1.52
v2.1.53
v2.1.55
v2.1.56
v2.1.58
v2.1.59
v2.1.6
v2.1.61
v2.1.62
v2.1.63
v2.1.66
v2.1.68
v2.1.69
v2.1.7
v2.1.70
v2.1.71
v2.1.72
v2.1.73
v2.1.74
v2.1.75
v2.1.76
v2.1.77
v2.1.78
v2.1.79
v2.1.80
v2.1.81
v2.1.83
v2.1.84
v2.1.85
v2.1.86
v2.1.87
v2.1.88
v2.1.89
v2.1.9
v2.1.90
v2.1.91
v2.1.92
v2.1.94
v2.1.96
v2.1.97
v2.1.98

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-103435.json"