---
id: CVE-2026-46406
title: >-
  @anthropic-ai/claude-code has an Insecure Temporary File in /copy Command that
  Enables Response Disclosure and Symlink-Based File Write
summary: >-
  @anthropic-ai/claude-code has an Insecure Temporary File in /copy Command that
  Enables Response Disclosure and Symlink-Based File Write
severity: medium
cwe:
  - CWE-59
  - CWE-200
  - CWE-377
vendor: anthropic-ai
product: '@anthropic-ai/claude-code'
ecosystem: npm
affected:
  - '@anthropic-ai/claude-code >= 2.1.59, < 2.1.128'
patched:
  - '@anthropic-ai/claude-code 2.1.128'
published: '2026-06-25'
updated: '2026-06-25'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-4vp2-6q8c-pvq2'
references:
  - url: >-
      https://github.com/anthropics/claude-code/security/advisories/GHSA-4vp2-6q8c-pvq2
  - url: 'https://github.com/advisories/GHSA-4vp2-6q8c-pvq2'
tags:
  - ghsa
  - npm
ingestedAt: '2026-06-26T16:43:14.249Z'
epss: 0.00154
epssPercentile: 0.03748
---

## Overview

The Claude Code `/copy` command wrote responses to a hardcoded, predictable path (`/tmp/claude/response.md`) without UID isolation, randomness, or symlink protection. The file was created world-readable (0644) in a world-traversable directory (0755), allowing any local user to read a privileged user's Claude response, which could contain secrets or credentials. Additionally, because the path was static and predictable, a local attacker could pre-create the directory and plant a symlink at the expected file path, causing the privileged process to follow the symlink and overwrite an attacker-chosen file with the response text. Exploiting this required a local unprivileged user on the same system and a privileged user to run the `/copy` command.

Users on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to the latest version.

Claude Code thanks hackerone.com/c_h4ck_0 for reporting this issue.

## Affected packages

- `@anthropic-ai/claude-code >= 2.1.59, < 2.1.128`

## Remediation

Upgrade to a patched release:

- `@anthropic-ai/claude-code 2.1.128`
