Vulnerability Database

296,748

Total vulnerabilities in the database

CVE-2025-59829

Claude Code failed to account for symlinks when checking permission deny rules. If a user explicitly denied Claude Code access to a file and Claude Code had access to a symlink pointing to that file, it was possible for Claude Code to access the file.

Users on standard Claude Code auto-update will have received this fix automatically. Users performing manual updates are advised to update to the latest version.

Thank you to https://hackerone.com/vinai for reporting this issue!

No technical information available.

CWEs: