CVE-2026-25724
Claude Code has Permission Deny Bypass Through Symbolic Links
EPSS 0.38%
描述
Claude Code failed to strictly enforce deny rules configured in settings.json when accessing files through symbolic links. If a user explicitly denied Claude Code access to a file (such as /etc/passwd) and Claude Code had access to a symbolic link pointing to that file, it was possible for Claude Code to read the restricted file through the symlink without triggering deny rule enforcement. Users on standard Claude Code auto-update received this fix automatically. Users performing manual updates are advised to update to the latest version. Claude Code thanks https://hackerone.com/ofirh for reporting this issue.
如何修補 CVE-2026-25724
要修補 CVE-2026-25724,請將受影響套件升級到下列已修補版本。
- —升級至 2.1.7 或更新版本
CVE-2026-25724 正在被利用嗎?
低 — EPSS 為 0.4%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 2.1.7
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N |