CVE-2026-46406: Claude Code: Insecure Temporary File in /copy Command Enables Response Disclosure and Symlink-Based File Write

Published Jun 25, 2026
·
Updated

Claude Code is an agentic coding tool. From 2.1.59 until 2.1.128, the Claude Code /copy command wrote responses to a hardcoded, predictable path (/tmp/claude/response.md) without UID isolation, randomness, or symlink protection. The file was created world-readable (0644) in a world-traversable directory (0755), allowing any local user to read a privileged user's Claude response, which could contain secrets or credentials. Additionally, because the path was static and predictable, a local attacker could pre-create the directory and plant a symlink at the expected file path, causing the privileged process to follow the symlink and overwrite an attacker-chosen file with the response text. Exploiting this required a local unprivileged user on the same system and a privileged user to run the /copy command. This vulnerability is fixed in 2.1.128.

Other sources

The Claude Code /copy command wrote responses to a hardcoded, predictable path (/tmp/claude/response.md) without UID isolation, randomness, or symlink protection. The file was created world-readable (0644) in a world-traversable directory (0755), allowing any local user to read a privileged user's Claude response, which could contain secrets or credentials. Additionally, because the path was static and predictable, a local attacker could pre-create the directory and plant a symlink at the expected file path, causing the privileged process to follow the symlink and overwrite an attacker-chosen file with the response text. Exploiting this required a local unprivileged user on the same system and a privileged user to run the /copy command.

Users on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to the latest version.

Claude Code thanks hackerone.com/ch4ck0 for reporting this issue.

GitHub

Affected Software

2 affected componentsFixes available
npm/@anthropic-ai/claude-code>=2.1.59<2.1.128
2.1.128
Anthropic Claude Code Node.js>=2.1.58<2.1.128

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/@anthropic-ai/claude-code to a version that resolves this vulnerability.

    Fixed in 2.1.128
  2. Upgrade

    Upgrade Claude Code to a version that resolves this vulnerability.

    Fixed in 2.1.128
  3. Compensating control

    If manual updates are not yet complete, reduce exposure of Claude Code response files by restricting access to the world-traversable/writable temporary directory that previously contained the predictable path (/tmp/claude/response.md) (e.g., tighten permissions/contain the temp location) to prevent other local users from reading or planting symlinks there.

Event History

Jun 25, 2026
Advisory Published
via GitHub·04:53 PM
Data Sourced
via GitHub·04:53 PM
DescriptionWeaknessAffected Software
Jun 29, 2026
CVE Published
via MITRE·02:03 PM
Data Sourced
via MITRE·02:03 PM
DescriptionWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-46406?

The severity of CVE-2026-46406 is classified as risk level 47.

2

How do I fix CVE-2026-46406?

To fix CVE-2026-46406, ensure the `/copy` command does not write to predictable paths and implement proper UID isolation and symlink protection.

3

What type of vulnerability is associated with CVE-2026-46406?

CVE-2026-46406 is associated with information leakage due to inadequate file permissions and path predictability.

4

Who is affected by CVE-2026-46406?

Users of npm/@anthropic-ai/claude-code are affected by CVE-2026-46406 due to the insecure handling of file responses.

5

When was CVE-2026-46406 published?

CVE-2026-46406 was published on June 25, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203