Junglewise Threat Intelligence

CVE-2026-41686: Anthropic Claude SDK for TypeScript insecure file permissions in LocalFilesystemMemoryTool

CVE-2026-41686 · Severity: medium · CVSS 4.4 · Published 2026-05-04

Vendors: npm, Anthropic.

Executive brief

The Anthropic Claude SDK for TypeScript contains a vulnerability where it creates temporary memory files and directories with overly permissive access settings. This allows other users on the same computer or within certain container environments to read or modify the AI agent's internal state. An attacker could use this to steal sensitive information from the AI's memory or manipulate the AI's future behavior.

Technical details

The BetaLocalFilesystemMemoryTool in the Anthropic TypeScript SDK (@anthropic-ai/sdk) fails to set restrictive file permissions when creating memory-persisted files and directories. It uses Node.js default modes (0o666 for files and 0o777 for directories), which makes these resources world-readable on systems with standard umasks and world-writable in environments with permissive umasks, such as certain Docker base images. A local attacker with low privileges can exploit this to read persisted agent state or modify memory files to influence model behavior. The issue is addressed in version 0.91.1 by ensuring more restrictive permission assignments.

Affected products

  • Anthropic @anthropic-ai/sdk >= 0.79.0, < 0.91.1

Timeline

  • 2026-04-24: disclosed: Vulnerability reported by lucasfutures
  • 2026-04-29: advisory: GitHub Advisory published
  • 2026-05-04: other: NVD published date

References

Related threats