CVE-2026-46406: Claude Code: Insecure Temporary File in /copy Command Enables Response Disclosure and Symlink-Based File Write
Claude Code is an agentic coding tool. From 2.1.59 until 2.1.128, the Claude Code /copy command wrote responses to a hardcoded, predictable path (/tmp/claude/response.md) without UID isolation, randomness, or symlink protection. The file was created world-readable (0644) in a world-traversable directory (0755), allowing any local user to read a privileged user's Claude response, which could contain secrets or credentials. Additionally, because the path was static and predictable, a local attacker could pre-create the directory and plant a symlink at the expected file path, causing the privileged process to follow the symlink and overwrite an attacker-chosen file with the response text. Exploiting this required a local unprivileged user on the same system and a privileged user to run the /copy command. This vulnerability is fixed in 2.1.128.
Other sources
The Claude Code /copy command wrote responses to a hardcoded, predictable path (/tmp/claude/response.md) without UID isolation, randomness, or symlink protection. The file was created world-readable (0644) in a world-traversable directory (0755), allowing any local user to read a privileged user's Claude response, which could contain secrets or credentials. Additionally, because the path was static and predictable, a local attacker could pre-create the directory and plant a symlink at the expected file path, causing the privileged process to follow the symlink and overwrite an attacker-chosen file with the response text. Exploiting this required a local unprivileged user on the same system and a privileged user to run the /copy command.
Users on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to the latest version.
Claude Code thanks hackerone.com/ch4ck0 for reporting this issue.
— GitHub
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@anthropic-ai/claude-codeto a version that resolves this vulnerability.Fixed in 2.1.128 - Upgrade
Upgrade
Claude Codeto a version that resolves this vulnerability.Fixed in 2.1.128 - Compensating control
If manual updates are not yet complete, reduce exposure of Claude Code response files by restricting access to the world-traversable/writable temporary directory that previously contained the predictable path (/tmp/claude/response.md) (e.g., tighten permissions/contain the temp location) to prevent other local users from reading or planting symlinks there.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46406?
The severity of CVE-2026-46406 is classified as risk level 47.
How do I fix CVE-2026-46406?
To fix CVE-2026-46406, ensure the `/copy` command does not write to predictable paths and implement proper UID isolation and symlink protection.
What type of vulnerability is associated with CVE-2026-46406?
CVE-2026-46406 is associated with information leakage due to inadequate file permissions and path predictability.
Who is affected by CVE-2026-46406?
Users of npm/@anthropic-ai/claude-code are affected by CVE-2026-46406 due to the insecure handling of file responses.
When was CVE-2026-46406 published?
CVE-2026-46406 was published on June 25, 2026.