---
id: CVE-2026-103435
title: >-
  Claude Code validated that a target file path resided within the project
  working directory at permission-check time, but re-resolved the path at write
  time without repeating that validation
summary: >-
  Claude Code validated that a target file path resided within the project
  working directory at permission-check time, but re-resolved the path at write
  time without repeating that validation. This time-of-check to time-of-use
  (TOCTOU) gap…
severity: high
cvss: 7.7
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-22
  - CWE-61
  - CWE-367
vendor: Anthropic
product: '@anthropic-ai/claude-code'
affected:
  - '@anthropic-ai/claude-code < 2.1.129'
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T15:16:57.037'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103435'
references:
  - url: >-
      https://github.com/anthropics/claude-code/security/advisories/GHSA-5j29-h97v-84ch
    label: 98a01053-8a31-4f6d-9aa9-252be161adc6
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-10-07T14:39:02.916533Z'
cvssSource: cna
ingestedAt: '2026-10-07T13:31:04.595Z'
---

## Overview

Claude Code validated that a target file path resided within the project working directory at permission-check time, but re-resolved the path at write time without repeating that validation. This time-of-check to time-of-use (TOCTOU) gap allowed an attacker who could write to the workspace to atomically replace a project file with a symlink, causing Claude Code to follow the symlink and write its output to an arbitrary file outside the project sandbox. Exploitation required the ability to win a race condition against the write operation and write access to the shared workspace, enabling a lower-privileged attacker to redirect benign edits to sensitive files (e.g., shell configuration) in a higher-privileged session.

Users on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to the latest version.

Thank you to hackerone.com/c_h4ck_0 for reporting this issue.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
