CVE 2.3 LOW

Claude Code: Permission deny bypass is possible through symlink_CVE-2025-59829

2.3 / 10
LOW
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Description

Claude Code is an agentic coding tool. Versions below 1.0.120 failed to account for symlinks when checking permission deny rules. If a user explicitly denied Claude Code access to a file and Claude Code had access to a symlink pointing to that file, it was possible for Claude Code to access the file. Users on standard Claude Code auto-update will have received this fix automatically. Users performing manual updates are advised to update to the latest version. This issue is fixed in version 1.0.120.

Basic Information

ID CVE-2025-59829
Source GitHub_M
Published Oct 3, 2025 at 20:03

Affected Product

Vendor anthropics
Product claude-code
Version < 1.0.120
Affected Versions anthropics claude-code < 1.0.120

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.