Executive brief
Claude Code is a code execution environment that sandboxes untrusted code to prevent it from accessing files outside a designated workspace. A vulnerability in symlink handling allows an attacker to bypass this sandbox by creating symlinks that point outside the workspace, then writing through those symlinks to arbitrary locations on the system. Combined with prompt injection attacks, this could lead to arbitrary code execution outside the sandbox.
Technical details
The vulnerability is a path traversal/sandbox escape in Claude Code's file handling logic (CWE-22, CWE-61). The sandboxed process can create symlinks pointing to locations outside the workspace, which the unsandboxed Claude Code process subsequently follows without validation. When Claude Code writes to a path that passes through such a symlink, it bypasses workspace boundary checks and writes to the target location without user confirmation. Attack requires the ability to inject untrusted code into Claude Code's context (via prompt injection) to trigger sandbox execution. The vulnerability allows arbitrary file writes outside the sandbox, potentially enabling code execution. A fix was released in version 2.1.64 and auto-deployed to standard users.
Affected products
- Anthropic Claude Code < 2.1.64
Timeline
- 2026-04-21: disclosed
- 2026-04-21: patched: Fixed in version 2.1.64