CVE-2026-46406 Details
Description
Claude Code is an agentic coding tool. From 2.1.59 until 2.1.128, the Claude Code /copy command wrote responses to a hardcoded, predictable path (/tmp/claude/response.md) without UID isolation, randomness, or symlink protection. The file was created world-readable (0644) in a world-traversable directory (0755), allowing any local user to read a privileged user's Claude response, which could contain secrets or credentials. Additionally, because the path was static and predictable, a local attacker could pre-create the directory and plant a symlink at the expected file path, causing the privileged process to follow the symlink and overwrite an attacker-chosen file with the response text. Exploiting this required a local unprivileged user on the same system and a privileged user to run the /copy command. This vulnerability is fixed in 2.1.128.
A vulnerability exists in Claude Code versions 2.1.59 prior to 2.1.128, where the '/copy' command writes responses to a hardcoded, predictable path '/tmp/claude/response.md'. This implementation lacks UID isolation, randomness, and symlink protection. The file is created with world-readable permissions in a directory that is accessible to all users, enabling local users to read sensitive responses from privileged users. Furthermore, the predictable file path allows local attackers to create a symlink at the expected location, directing the privileged process to overwrite a file of their choice with the response text. Exploitation requires a local unprivileged user and a privileged user to execute the '/copy' command.
Users on standard Claude Code auto-update have received this fix. Those performing manual updates should update to the latest version.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/anthropics/claude-code/security/advisories/GHSA-4vp2-6q8c-pvq2 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
| CWE-377 | Insecure Temporary File | [email protected] |
| CWE-59 | Improper Link Resolution Before File Access ('Link Following') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| anthropic claude code | >= 2.1.58, < 2.1.128 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 30, 2026 | Initial Analysis | [email protected] |
| Jun 29, 2026 | CVE Modified | CISA-ADP |
| Jun 29, 2026 | New CVE Received | [email protected] |