Junglewise Threat Intelligence

CVE-2025-59829: Anthropic Claude Code permission bypass via symlink

CVE-2025-59829 · Severity: medium · CVSS 4 · Published 2025-10-03

Technologies: Anthropic Claude Code, @anthropic-ai/claude-code (npm). Vendors: Anthropic, npm.

Executive brief

Claude Code is an AI-powered code editor extension that respects user-configured file access restrictions. A vulnerability allowed Claude Code to bypass explicit file access denials by following symlinks to restricted files. An attacker could exploit this to access sensitive files that a user had explicitly blocked, potentially exposing confidential code or project data.

Technical details

Claude Code failed to canonicalize file paths when evaluating permission deny rules, specifically not accounting for symbolic links (symlinks). If a user denied Claude Code access to a file via explicit permission rules, an attacker could create or leverage a symlink pointing to that file and access it through the symlink, bypassing the deny check. This is a path traversal / access control bypass vulnerability (CWE-61: Improper Link Resolution Before File Access). The attack requires network access (to the Claude Code service) and user interaction (to trigger file access), but requires no authentication or special privileges. The vulnerability was patched in version 1.0.120; earlier versions are affected.

Affected products

  • Anthropic Claude Code < 1.0.120

Timeline

  • 2025-10-03: disclosed: Advisory published
  • 2025-10-03: patched: Fix available in version 1.0.120

References

Related threats