Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2026-103435 Details

Description

Claude Code validated that a target file path resided within the project working directory at permission-check time, but re-resolved the path at write time without repeating that validation. This time-of-check to time-of-use (TOCTOU) gap allowed an attacker who could write to the workspace to atomically replace a project file with a symlink, causing Claude Code to follow the symlink and write its output to an arbitrary file outside the project sandbox. Exploitation required the ability to win a race condition against the write operation and write access to the shared workspace, enabling a lower-privileged attacker to redirect benign edits to sensitive files (e.g., shell configuration) in a higher-privileged session. Users on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to the latest version. Thank you to hackerone.com/c_h4ck_0 for reporting this issue.

Metrics

CVSS 3.x Severity and Vector Strings:

No CVSS 3.x data is available for this CVE.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://github.com/anthropics/claude-code/security/advisories/GHSA-5j29-h97v-84ch 98a01053-8a31-4f6d-9aa9-252be161adc6

Weakness Enumeration

CWE-IDCWE NameSource
CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')98a01053-8a31-4f6d-9aa9-252be161adc6
CWE-367Time-of-check Time-of-use (TOCTOU) Race Condition98a01053-8a31-4f6d-9aa9-252be161adc6
CWE-61UNIX Symbolic Link (Symlink) Following98a01053-8a31-4f6d-9aa9-252be161adc6

Affected Products

No affected product data is available for this CVE.

Change History

2 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2026-103435
NVD Published Date:
Oct 7, 2026
NVD Last Modified:
Oct 7, 2026
Source:
98a01053-8a31-4f6d-9aa9-252be161adc6
CVE-2026-103435 Details - Not Deferred