CVE-2025-59829

Claude Code is an agentic coding tool. Versions below 1.0.120 failed to account for symlinks when checking permission deny rules. If a user explicitly denied Claude Code access to a file and Claude Code had access to a symlink pointing to that file, it was possible for Claude Code to access the file. Users on standard Claude Code auto-update will have received this fix automatically. Users performing manual updates are advised to update to the latest version. This issue is fixed in version 1.0.120.
Configurations

Configuration 1 (hide)

cpe:2.3:a:anthropic:claude_code:*:*:*:*:*:node.js:*:*

History

24 Oct 2025, 19:45

Type Values Removed Values Added
CPE cpe:2.3:a:anthropic:claude_code:*:*:*:*:*:node.js:*:*
First Time Anthropic
Anthropic claude Code
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
References () https://github.com/anthropics/claude-code/security/advisories/GHSA-66m2-gx93-v996 - () https://github.com/anthropics/claude-code/security/advisories/GHSA-66m2-gx93-v996 - Vendor Advisory

03 Oct 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-03 20:15

Updated : 2025-10-24 19:45


NVD link : CVE-2025-59829

Mitre link : CVE-2025-59829

CVE.ORG link : CVE-2025-59829


JSON object : View

Products Affected

anthropic

  • claude_code
CWE
CWE-61

UNIX Symbolic Link (Symlink) Following