UNIX symbolic link following in Claude Code - CVE-2025-59829
Published: April 30, 2026
Claude Code
Anthropic
Description
The vulnerability allows a remote attacker to access denied files through a symlink.
The vulnerability exists due to unix symbolic link following in permission deny rule checks when resolving access to a symlink pointing to a denied file. A remote attacker can provide or use a symlink to a denied file to access denied files through a symlink.
User interaction is required.