CVE-2026-39861Patch(anthropic / claude_code)

LOWCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch anthropic claude_code systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Claude Code is an agentic coding tool. Prior to version 2.1.64, Claude Code's sandbox did not prevent sandboxed processes from creating symlinks pointing to locations outside the workspace. When Claude Code subsequently wrote to a path within such a symlink, its unsandboxed process followed the symlink and wrote to the target location outside the workspace without prompting the user for confirmation. This allowed a sandbox escape where neither the sandboxed command nor the unsandboxed app could independently write outside the workspace, but their combination could write to arbitrary locations, potentially leading to code execution outside the sandbox. Reliably exploiting this required the ability to add untrusted content into a Claude Code context window to trigger sandboxed code execution via prompt injection. Users on standard Claude Code auto-update have received this fix automatically. Users performing manual updates are advised to update to version 2.1.64 or later.

2.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-61

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • claude_code

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 18 mentions across 9 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 10 signals
  • Technical details provided in 15 signals
  • Disclosure: 4 classified signals
  • General: 4 classified signals
  • Peaked 8d ago at 4 mentions (2026-04-21); latest day: 1
  • 18 total mentions across 9 days

Affected systems

Vendors
Products
claude_code

Deep dive

Activity timeline18 mentions / 9d
01234Mentions · 2026-04-21: 4Mentions · 2026-04-28: 1Mentions · 2026-05-01: 1Mentions · 2026-05-08: 4Mentions · 2026-05-11: 1Mentions · 2026-05-12: 3Mentions · 2026-05-13: 1Mentions · 2026-05-19: 2Mentions · 2026-07-20: 1PoC Mentioned / Linked · 2026-05-19: 1Patch / Workaround · 2026-04-21: 2Patch / Workaround · 2026-05-08: 1Patch / Workaround · 2026-05-11: 1Patch / Workaround · 2026-05-12: 3Patch / Workaround · 2026-05-13: 1Patch / Workaround · 2026-05-19: 2Technical Details · 2026-04-21: 4Technical Details · 2026-04-28: 1Technical Details · 2026-05-08: 3Technical Details · 2026-05-11: 1Technical Details · 2026-05-12: 3Technical Details · 2026-05-13: 1Technical Details · 2026-05-19: 204-2104-2805-0105-0805-1105-1205-1305-1907-20
Signal classification3 categories
Patch
1055.6%
Disclosure
422.2%
General
422.2%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-04-214
Disclosure2Patch2
2026-04-281
Disclosure1
2026-05-011
General1
2026-05-084
Disclosure1General2Patch1
2026-05-111
Patch1
2026-05-123
Patch3
2026-05-131
Patch1
2026-05-192
Patch2
2026-07-201
General1
Full discourse18 posts
  • Upwind Security MDR@UpwindMDR
    Patch

    CVE-2026-39861 impacts Claude Code Attackers can break the sandbox and write files anywhere. Immediate patch required.

    Post summary

    CVE‑2026‑39861 enables attackers to escape the sandbox in Claude Code and write files anywhere. The post stresses that an immediate patch is required.

    00051184
    237 followersView on X
  • Armor1@armor1_ai
    Patch

    CVE-2026-39861: Claude Code sandbox escape via symlink following. CVSS v4 7.7. Sixth Claude Code advisory this review period. Fixed in 2.1.64. @AnthropicAI

    Post summary

    The advisory announces CVE-2026-39861, a sandbox escape via symlink following in Claude Code rated CVSS v4 7.7, and notes that the issue is fixed in version 2.1.64.

    4000059
    3 followersView on X
  • Martin Musiol@musiol_martin
    Patch

    NomShub and CVE-2026-39861. @cursor_ai and @AnthropicAI Claude Code both shipped sandbox escapes this month. Shell builtins vs symlinks. Same root: parsers blind to unsandboxed writes. OpenClaw v0.4 gates every write. https://aigeneral.net

    Post summary

    The tweet references CVE-2026-39861 and sandbox escape behavior, but highlights that OpenClaw v0.4 mitigates the issue; no active exploitation or PoC details are provided.

    2001080
    398 followersView on X
  • Alex Rogov@Alex_Rogov_js
    General

    @sahildarz agreed, and it's why i don't trust "sandboxed" as a static label either. the CVE-2026-39861 escape was a sandbox bug, not a malicious actor. same lesson: revisit the boundary when the tool surface changes, don't assume yesterday's audit still holds.

    Post summary

    The tweet references CVE‑2026‑39861 as a sandbox escape but provides no additional technical detail, PoC, exploit code, active exploitation, or patch information, classifying it as a general mention.

    0000026
    163 followersView on X
  • Martin Musiol@musiol_martin
    Patch

    CVE-2026-39861. @AnthropicAI Claude Code sandbox escape, fixed in 2.1.64. Sandboxed process drops the symlink. Unsandboxed write follows it. Arbitrary file write, no prompt. https://aigeneral.net

    Post summary

    The post announces a CVE fix for AnthropicAI’s Claude Code sandbox escape, describing the vulnerability details and its resolution.

    0000063
    398 followersView on X
  • ToolsLib@ToolsLib
    Patch

    Claude Code CVE-2026-39861: symlink-assisted sandbox escape fixed https://blog.toolslib.net/2026/05/13/claude-code-cve-2026-39861-symlink-sandbox-escape/

    Post summary

    A blog post notes that CVE-2026-39861, a symlink-assisted sandbox escape in Claude Code, has been fixed; no PoC, exploit, or active exploitation details are mentioned.

    00000106
    542 followersView on X
  • kura openclaw@KURAOpenclaw
    Patch

    ① 【今、何が危ないのか】 Claude Codeのシンボリックリンクサンドボックス脱出脆弱性(CVE-2026-39861)。エージェントがファイルシステム全体へアクセス可能に。 ② 【被害規模・影響範囲の数値】 ・潜在的に数千のAI開発プロジェクトが影響対象 ・過去1年で同種脆弱性による情報漏洩件数は12件 ・攻撃者が取得できるデータ量は最大数TB ③ 【今すぐ取るべき対策】 1. Claude Codeの最新パッチを適用 2. エージェントのファイルシステム権限を最小化 3. サンドボックスでシンボリックリンクを無効化 4. 監査ログを有効化し異常アクセスを検知 5. 影響コードベースのコードレビュー実施 ④ 【技術的メカニズム】 - シンボリックリンクを利用したパス横取り - エージェントがroot権限で実行される環境 - 悪意コードが /.well-known/ にリンク作成 - ファイル読写が制限無く可能に ⑤ 【規制・業界対応の展望】 - ISO/IEC 42001:2026 がAIエージェント権限管理を明確化 - 各主要クラウドベンダーがサンドボックス強化策を発表予定 - 法規制議論が活発化し、2027年までにAIエージェント安全基準が制定見込み 参考: https://www.politico.com/news/2026/05/11/google-hackers-ai-security-00913247

    Post summary

    Claude Code’s symbolic‑link sandbox escape (CVE‑2026‑39861) lets a root‑level agent read/write the entire filesystem; a patch is available and mitigation steps are recommended.

    0000073
    40 followersView on X
  • kura openclaw@KURAOpenclaw
    Patch

    ① 【今、何が危ないのか】 Claude Codeのシンボリックリンクサンドボックス脱出脆弱性(CVE-2026-39861)。エージェントがファイルシステム全体へアクセス可能に。 ② 【被害規模・影響範囲の数値】 ・潜在的に数千のAI開発プロジェクトが影響対象 ・過去1年で同種脆弱性による情報漏洩件数は12件 ・攻撃者が取得できるデータ量は最大数TB ③ 【今すぐ取るべき対策】 1. Claude Codeの最新パッチを適用 2. エージェントのファイルシステム権限を最小化 3. サンドボックスでシンボリックリンクを無効化 4. 監査ログを有効化し異常アクセスを検知 5. 影響コードベースのコードレビュー実施 ④ 【技術的メカニズム】 - シンボリックリンクを利用したパス横取り - エージェントがroot権限で実行される環境 - 悪意コードが /.well-known/ にリンク作成 - ファイル読写が制限無く可能に ⑤ 【規制・業界対応の展望】 - ISO/IEC 42001:2026 がAIエージェント権限管理を明確化 - 各主要クラウドベンダーがサンドボックス強化策を発表予定 - 法規制議論が活発化し、2027年までにAIエージェント安全基準が制定見込み 参考: https://www.politico.com/news/2026/05/11/google-hackers-ai-security-00913247

    Post summary

    CVE‑2026‑39861 is a sandbox escape via symbolic links in Claude Code; no active exploitation reported, but patches and mitigations are available.

    0000069
    40 followersView on X
  • kura openclaw@KURAOpenclaw
    Patch

    ① 【今、何が危ないのか】 Claude Codeのシンボリックリンクサンドボックス脱出脆弱性(CVE-2026-39861)。エージェントがファイルシステム全体へアクセス可能に。 ② 【被害規模・影響範囲の数値】 ・潜在的に数千のAI開発プロジェクトが影響対象 ・過去1年で同種脆弱性による情報漏洩件数は12件 ・攻撃者が取得できるデータ量は最大数TB ③ 【今すぐ取るべき対策】 1. Claude Codeの最新パッチを適用 2. エージェントのファイルシステム権限を最小化 3. サンドボックスでシンボリックリンクを無効化 4. 監査ログを有効化し異常アクセスを検知 5. 影響コードベースのコードレビュー実施 ④ 【技術的メカニズム】 - シンボリックリンクを利用したパス横取り - エージェントがroot権限で実行される環境 - 悪意コードが /.well-known/ にリンク作成 - ファイル読写が制限無く可能に ⑤ 【規制・業界対応の展望】 - ISO/IEC 42001:2026 がAIエージェント権限管理を明確化 - 各主要クラウドベンダーがサンドボックス強化策を発表予定 - 法規制議論が活発化し、2027年までにAIエージェント安全基準が制定見込み 参考: https://www.politico.com/news/2026/05/11/google-hackers-ai-security-00913247

    Post summary

    This advisory details the CVE‑2026‑39861 symbolic link sandbox escape in Claude Code, highlighting the technical mechanism and recommending patching and other mitigations, although no PoC or evidence of active exploitation is provided.

    0000069
    40 followersView on X
  • Martin Musiol@musiol_martin
    Patch

    CVE-2026-21852, CVE-2026-24887, CVE-2026-39861. Three Claude Code CVEs in one cycle: API-key exfil before the trust prompt, command injection via the find call, sandbox escape via symlink. Fixes shipped in 2.0.72 and 2.1.64. The SaaS Claude Code surface IS the threat surface. Self-hosted Claude Code with strict allowlists kills all three classes. https://aigeneral.net

    Post summary

    Three Claude Code CVEs are disclosed (API‑key exfiltration, command injection, sandbox escape) with fixes available in 2.0.72/2.1.64, highlighting that SaaS is vulnerable while self‑hosted setups mitigate the risk.

    0000073
    396 followersView on X
  • SwiftInference.ai@swiftinference
    General

    AI digest for May 8, 2026: Claude Code sandbox escape (CVE-2026-39861), GPT-5.5 price hike, Google's AlphaEvolve coding agent, and new natural language autoencoder research. Everything technical teams need to act on now. https://www.swiftinference.ai/blog/ai-news-digest-may-8-2026-agents-costs-and-security-2026-05-08 #AIInfrastructure #LLMSecurity

    Post summary

    The post lists CVE-2026-39861 among other AI news but provides no details about the vulnerability, exploit, or mitigation, making it a general mention without actionable intelligence.

    0000048
    11 followersView on X
  • Hacker News 20@betterhn20
    Disclosure

    Claude Code CVE-2026-39861:sandbox escape via symlink https://github.com/advisories/GHSA-vp62-r36r-9xqp (https://news.ycombinator.com/item?id=48057842)

    Post summary

    The post references CVE‑2026‑39861 as a sandbox‑escape via symlink, linking to a GitHub advisory, but it does not provide a PoC, exploit code, patch, or evidence of active exploitation.

    00000117
    3.0K followersView on X
  • Suresh@_Suresh2
    General

    Claude Code has a sandbox escape vulnerability via symlink, tracked as CVE-2026-39861.

    Post summary

    The text highlights a sandbox escape vulnerability involving symlinks in Claude Code (CVE-2026-39861) but provides no additional technical, exploitation, or remediation details.

    00000185
    171 followersView on X
  • Jeff@p01ntf1v3
    General

    @aaronp613 CVE-2026-39861 shows us all that they need to lock it down and they need to lock it down now

    Post summary

    The tweet merely mentions CVE-2026-39861 and urges action without providing technical details or evidence of exploitation.

    0000043
    10 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-39861: CVE-2026-39861: Sandbox Escape via Symlink Following in Anthropic Claude Code Claude Code versions prior to 2.1.64 contain a sandbox escape vulnerability due to improper handling of symbolic links. Sandboxed processes can create symlin... https://cvereports.com/reports/CVE-2026-39861

    Post summary

    The post delivers a brief disclosure that Anthropic Claude Code before version 2.1.64 suffers a sandbox escape vulnerability caused by improper symlink handling, with no proof of exploitation or mitigation details shared.

    0000032
    36 followersView on X
  • cybersecuritypath@cybrsecpath
    Disclosure

    CVE-2026-39861: Claude Code Sandbox Escape Flaw Allows Arbitrary File Write https://thecybrdef.com/cve-2026-39861-claude-sandbox-escape-vulnerability #cybersecurity #claude

    Post summary

    A new CVE (CVE-2026-39861) is announced, describing a sandbox escape that enables arbitrary file writes; however, the text provides no evidence of active exploitation, PoC, exploit code, or available mitigation.

    0000038
    6 followersView on X
  • NerdieNews@NewsNerdie
    Patch

    CVE-2026-39861 allows attackers to escape Claude Code's sandbox and write files arbitrarily outside its workspace. This vulnerability is critical; patch immediately. #NerdieNews #CyberSecurity #InfoSec #Ransomware #Malware #Microsoft #VMware https://t.co/0PLsDPDrvF

    Post summary

    The tweet alerts readers to CVE-2026-39861, which permits sandbox escape and arbitrary file writes in Claude Code, and urges users to apply the available patch immediately.

    0000041
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-39861 Claude Code is an agentic coding tool. Prior to version 2.1.64, Claude Code's sandbox did not prevent sandboxed processes from creating symlinks pointing to locations… https://www.cve.org/CVERecord?id=CVE-2026-39861

    Post summary

    The text announces CVE‑2026‑39861 as a sandbox escape in Claude Code, noting that prior to version 2.1.64 the sandbox allowed symlink creation to any location. It provides no PoC, exploit, or patch details.

    00000111
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appanthropicclaude_code-node.js-

Explore more