GHSA-4q92-rfm6-2cqx

Suggest an improvement
Source
https://github.com/advisories/GHSA-4q92-rfm6-2cqx
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-4q92-rfm6-2cqx/GHSA-4q92-rfm6-2cqx.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-4q92-rfm6-2cqx
Aliases
Published
2026-02-06T19:08:04Z
Modified
2026-04-12T05:17:45Z
Severity
  • 2.3 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
Claude Code has Permission Deny Bypass Through Symbolic Links
Details

Claude Code failed to strictly enforce deny rules configured in settings.json when accessing files through symbolic links. If a user explicitly denied Claude Code access to a file (such as /etc/passwd) and Claude Code had access to a symbolic link pointing to that file, it was possible for Claude Code to read the restricted file through the symlink without triggering deny rule enforcement.

Users on standard Claude Code auto-update received this fix automatically. Users performing manual updates are advised to update to the latest version.

Claude Code thanks https://hackerone.com/ofirh for reporting this issue.

Database specific
{
    "cwe_ids":  [
        "CWE-285",
        "CWE-61"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-02-06T19:08:04Z",
    "nvd_published_at":  "2026-02-06T18:16:00Z",
    "severity":  "LOW"
}
References

Affected packages

npm / @anthropic-ai/claude-code

Package

Name
@anthropic-ai/claude-code
View open source insights on deps.dev
Purl
pkg:npm/%40anthropic-ai/claude-code

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.1.7

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-4q92-rfm6-2cqx/GHSA-4q92-rfm6-2cqx.json"