Executive brief
Claude Code is an AI-powered code editor extension that respects user-configured file access restrictions. A vulnerability allowed Claude Code to bypass explicit file access denials by following symlinks to restricted files. An attacker could exploit this to access sensitive files that a user had explicitly blocked, potentially exposing confidential code or project data.
Technical details
Claude Code failed to canonicalize file paths when evaluating permission deny rules, specifically not accounting for symbolic links (symlinks). If a user denied Claude Code access to a file via explicit permission rules, an attacker could create or leverage a symlink pointing to that file and access it through the symlink, bypassing the deny check. This is a path traversal / access control bypass vulnerability (CWE-61: Improper Link Resolution Before File Access). The attack requires network access (to the Claude Code service) and user interaction (to trigger file access), but requires no authentication or special privileges. The vulnerability was patched in version 1.0.120; earlier versions are affected.
Affected products
- Anthropic Claude Code < 1.0.120
Timeline
- 2025-10-03: disclosed: Advisory published
- 2025-10-03: patched: Fix available in version 1.0.120