UNIX symbolic link following in Claude Code - CVE-2026-25724
Published: April 30, 2026
Claude Code
Anthropic
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to unix symbolic link following in deny rule enforcement for file access when accessing files through symbolic links. A remote attacker can cause Claude Code to read a denied file via a symbolic link to disclose sensitive information.
User interaction is required.