Claude Code is an agentic coding tool. Versions below 1.0.120 failed to account for symlinks when checking permission deny rules. If a user explicitly denied Claude Code access to a file and Claude Code had access to a symlink pointing to that file, it was possible for Claude Code to access the file. Users on standard Claude Code auto-update will have received this fix automatically. Users performing manual updates are advised to update to the latest version. This issue is fixed in version 1.0.120.
Metrics
Affected Vendors & Products
References
History
Fri, 03 Oct 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 03 Oct 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Claude Code is an agentic coding tool. Versions below 1.0.120 failed to account for symlinks when checking permission deny rules. If a user explicitly denied Claude Code access to a file and Claude Code had access to a symlink pointing to that file, it was possible for Claude Code to access the file. Users on standard Claude Code auto-update will have received this fix automatically. Users performing manual updates are advised to update to the latest version. This issue is fixed in version 1.0.120. | |
Title | Claude Code: Permission deny bypass is possible through symlink | |
Weaknesses | CWE-61 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-10-03T20:45:39.617Z
Reserved: 2025-09-22T14:34:03.471Z
Link: CVE-2025-59829

Updated: 2025-10-03T20:24:23.841Z

Status : Received
Published: 2025-10-03T20:15:33.653
Modified: 2025-10-03T20:15:33.653
Link: CVE-2025-59829

No data.

No data.