CVE-2025-59829

Claude Code is an agentic coding tool. Versions below 1.0.120 failed to account for symlinks when checking permission deny rules. If a user explicitly denied Claude Code access to a file and Claude Code had access to a symlink pointing to that file, it was possible for Claude Code to access the file. Users on standard Claude Code auto-update will have received this fix automatically. Users performing manual updates are advised to update to the latest version. This issue is fixed in version 1.0.120.
CVSS

No CVSS.

Configurations

No configuration.

History

03 Oct 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-03 20:15

Updated : 2025-10-03 20:15


NVD link : CVE-2025-59829

Mitre link : CVE-2025-59829

CVE.ORG link : CVE-2025-59829


JSON object : View

Products Affected

No product.

CWE
CWE-61

UNIX Symbolic Link (Symlink) Following