{"id":"CVE-2026-46406","title":"@anthropic-ai/claude-code has an Insecure Temporary File in /copy Command that Enables Response Disclosure and Symlink-Based File Write","summary":"@anthropic-ai/claude-code has an Insecure Temporary File in /copy Command that Enables Response Disclosure and Symlink-Based File Write","severity":"medium","cwe":["CWE-59","CWE-200","CWE-377"],"vendor":"anthropic-ai","product":"@anthropic-ai/claude-code","ecosystem":"npm","affected":["@anthropic-ai/claude-code >= 2.1.59, < 2.1.128"],"patched":["@anthropic-ai/claude-code 2.1.128"],"published":"2026-06-25","updated":"2026-06-25","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-4vp2-6q8c-pvq2","references":[{"url":"https://github.com/anthropics/claude-code/security/advisories/GHSA-4vp2-6q8c-pvq2"},{"url":"https://github.com/advisories/GHSA-4vp2-6q8c-pvq2"}],"tags":["ghsa","npm"],"ingestedAt":"2026-06-26T16:43:14.249Z","epss":0.00154,"epssPercentile":0.04867,"slug":"CVE-2026-46406","body":"## Overview\n\nThe Claude Code `/copy` command wrote responses to a hardcoded, predictable path (`/tmp/claude/response.md`) without UID isolation, randomness, or symlink protection. The file was created world-readable (0644) in a world-traversable directory (0755), allowing any local user to read a privileged user's Claude response, which could contain secrets or credentials. Additionally, because the path was static and predictable, a local attacker could pre-create the directory and plant a symlink at the expected file path, causing the privileged process to follow the symlink and overwrite an attacker-chosen file with the response text. Exploiting this required a local unprivileged user on the same system and a privileged user to run the `/copy` command.\n\nUsers on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to the latest version.\n\nClaude Code thanks hackerone.com/c_h4ck_0 for reporting this issue.\n\n## Affected packages\n\n- `@anthropic-ai/claude-code >= 2.1.59, < 2.1.128`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `@anthropic-ai/claude-code 2.1.128`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}