PT-2026-33883 · Anthropic · Claude-Code

CVE-2026-39861

·

Published

2026-04-21

·

Updated

2026-08-13

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Claude Code versions prior to 2.1.64
Description Claude Code contains a sandbox escape flaw where sandboxed processes can create symbolic links (symlinks) pointing to locations outside the designated workspace. When the unsandboxed process writes to a path within such a symlink, it follows the link and writes to the target location outside the workspace without user confirmation. While neither the sandboxed command nor the unsandboxed application can write outside the workspace independently, their combination allows writing to arbitrary locations, which could potentially lead to code execution outside the sandbox. Successful exploitation requires the ability to introduce untrusted content into the context window to trigger sandboxed code execution through prompt injection, a technique where malicious instructions are embedded in inputs to manipulate the AI agent's behavior.
Recommendations Update Claude Code to version 2.1.64 or later.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-39861
GHSA-VP62-R36R-9XQP

Affected Products

Claude-Code