PT-2026-33883 · Anthropic · Claude-Code
CVE-2026-39861
·
Published
2026-04-21
·
Updated
2026-08-13
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Claude Code versions prior to 2.1.64
Description
Claude Code contains a sandbox escape flaw where sandboxed processes can create symbolic links (symlinks) pointing to locations outside the designated workspace. When the unsandboxed process writes to a path within such a symlink, it follows the link and writes to the target location outside the workspace without user confirmation. While neither the sandboxed command nor the unsandboxed application can write outside the workspace independently, their combination allows writing to arbitrary locations, which could potentially lead to code execution outside the sandbox. Successful exploitation requires the ability to introduce untrusted content into the context window to trigger sandboxed code execution through prompt injection, a technique where malicious instructions are embedded in inputs to manipulate the AI agent's behavior.
Recommendations
Update Claude Code to version 2.1.64 or later.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Claude-Code