CVE-2026-103435: Arbitrary File Write via Write-Time Symlink Following (TOCTOU) in Claude Code
Claude Code validated that a target file path resided within the project working directory at permission-check time, but re-resolved the path at write time without repeating that validation. This time-of-check to time-of-use (TOCTOU) gap allowed an attacker who could write to the workspace to atomically replace a project file with a symlink, causing Claude Code to follow the symlink and write its output to an arbitrary file outside the project sandbox. Exploitation required the ability to win a race condition against the write operation and write access to the shared workspace, enabling a lower-privileged attacker to redirect benign edits to sensitive files (e.g., shell configuration) in a higher-privileged session.
Users on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to the latest version.
Thank you to hackerone.com/ch4ck0 for reporting this issue.
Affected Software
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
The issue is relevant where a lower-privileged attacker can write to a shared Claude Code workspace while Claude Code runs in a higher-privileged session. The attacker must be able to replace a project file with a symlink during the vulnerable write window.
Does exploitation require any user interaction or special access?
The attacker does not need prior privileges in the higher-privileged session, but does need write access to the shared workspace and must win a race condition against Claude Code's write operation. The CVSS vector also indicates user interaction is required.
Are standard installations already fixed?
Users on standard Claude Code auto-update have already received the fix. Users who perform manual updates should update to the latest version.
What is the risk if updates cannot be applied immediately?
Avoid running higher-privileged Claude Code sessions in workspaces writable by lower-privileged or untrusted users. Restrict write access to shared project directories to reduce the opportunity to replace files with symlinks during writes.