CVE-2025-59829: Claude Code: Permission deny bypass is possible through symlink

Published Oct 3, 2025
·
Updated

Claude Code failed to account for symlinks when checking permission deny rules. If a user explicitly denied Claude Code access to a file and Claude Code had access to a symlink pointing to that file, it was possible for Claude Code to access the file.

Users on standard Claude Code auto-update will have received this fix automatically. Users performing manual updates are advised to update to the latest version.

Thank you to https://hackerone.com/vinai for reporting this issue!

Other sources

Claude Code is an agentic coding tool. Versions below 1.0.120 failed to account for symlinks when checking permission deny rules. If a user explicitly denied Claude Code access to a file and Claude Code had access to a symlink pointing to that file, it was possible for Claude Code to access the file. Users on standard Claude Code auto-update will have received this fix automatically. Users performing manual updates are advised to update to the latest version. This issue is fixed in version 1.0.120.

MITRE

Affected Software

2 affected componentsFixes available
npm/@anthropic-ai/claude-code<1.0.120
1.0.120
Anthropic Claude Code Node.js<1.0.120

Event History

Oct 3, 2025
Advisory Published
via GitHub·02:17 PM
Data Sourced
via GitHub·02:17 PM
DescriptionWeaknessAffected Software
CVE Published
via MITRE·08:03 PM
Data Sourced
via MITRE·08:03 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
Affected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-59829?

CVE-2025-59829 has a high severity level due to the potential unauthorized access to files via symlinks.

2

How do I fix CVE-2025-59829?

To fix CVE-2025-59829, update to version 1.0.120 or later of the @anthropic-ai/claude-code package.

3

What does CVE-2025-59829 involve?

CVE-2025-59829 involves Claude Code failing to properly handle symlinks, potentially allowing unauthorized file access.

4

Who is affected by CVE-2025-59829?

Users of versions prior to 1.0.120 of the @anthropic-ai/claude-code package are at risk from CVE-2025-59829.

5

Is there a workaround for CVE-2025-59829?

There is no specific workaround for CVE-2025-59829 aside from updating the affected software package.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203