CVE-2026-39861
CVE-2026-39861 is a critical-severity vulnerability in Anthropic Claude Code with a CVSS 3.x base score of 10.0. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-22.
Key facts
- Severity: Critical (CVSS 3.x base score 10.0)
- CVSS v4: 7.7
- EPSS exploit prediction: 1% (55th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-24033
- Weakness: CWE-22
- Affected product: Anthropic Claude Code
- Published:
- Last modified:
Description
Claude Code is an agentic coding tool. Prior to version 2.1.64, Claude Code's sandbox did not prevent sandboxed processes from creating symlinks pointing to locations outside the workspace. When Claude Code subsequently wrote to a path within such a symlink, its unsandboxed process followed the symlink and wrote to the target location outside the workspace without prompting the user for confirmation. This allowed a sandbox escape where neither the sandboxed command nor the unsandboxed app could independently write outside the workspace, but their combination could write to arbitrary locations, potentially leading to code execution outside the sandbox. Reliably exploiting this required the ability to add untrusted content into a Claude Code context window to trigger sandboxed code execution via prompt injection. Users on standard Claude Code auto-update have received this fix automatically. Users performing manual updates are advised to update to version 2.1.64 or later.
Frequently asked questions
- What is CVE-2026-39861?
- Claude Code is an agentic coding tool. Prior to version 2.1.64, Claude Code's sandbox did not prevent sandboxed processes from creating symlinks pointing to locations outside the workspace. When Claude Code subsequently wrote to a path within such a symlink, its unsandboxed process followed the symlink and wrote to the target location outside the workspace without prompting the user for confirmation. This allowed a sandbox escape where neither the sandboxed command nor the unsandboxed app could independently write outside the workspace, but their combination could write to arbitrary locations, potentially leading to code execution outside the sandbox. Reliably exploiting this required the ability to add untrusted content into a Claude Code context window to trigger sandboxed code execution via prompt injection. Users on standard Claude Code auto-update have received this fix automatically. Users performing manual updates are advised to update to version 2.1.64 or later.
- How severe is CVE-2026-39861?
- CVE-2026-39861 has a CVSS 3.x base score of 10.0, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2026-39861 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (55th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-39861?
- CVE-2026-39861 affects Anthropic Claude Code. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-39861?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- Does CVE-2026-39861 have an EU (EUVD) identifier?
- Yes. CVE-2026-39861 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-24033.
- When was CVE-2026-39861 published?
- CVE-2026-39861 was published on 2026-04-21 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:a:anthropic:claude_code:*:*:*:*:*:node.js:*:*
More vulnerabilities in Anthropic Claude Code
- CVE-2026-25725 — Critical (CVSS 10.0): Claude Code is an agentic coding tool. Prior to version 2.1.2, Claude Code's bubblewrap sandboxing mechanism failed to…
- CVE-2025-66032 — Critical (CVSS 9.8): Claude Code is an agentic coding tool. Prior to 1.0.93, Due to errors in parsing shell commands related to $IFS and…
- CVE-2025-64755 — Critical (CVSS 9.8): Claude Code is an agentic coding tool. Prior to version 2.0.31, due to an error in sed command parsing, it was possible…
- CVE-2025-65099 — Critical (CVSS 9.8): Claude Code is an agentic coding tool. Prior to version 1.0.39, when running on a machine with Yarn 3.0 or above,…
- CVE-2025-59828 — Critical (CVSS 9.8): Claude Code is an agentic coding tool. Prior to Claude Code version 1.0.39, when using Claude Code with Yarn versions…
- CVE-2025-59041 — Critical (CVSS 9.8): Claude Code is an agentic coding tool. At startup, Claude Code executed a command templated in with `git config…
All CVEs affecting Anthropic Claude Code →
Other CWE-22 (Path Traversal) vulnerabilities
- CVE-2026-55393 — Critical (CVSS 10.0): Unvalidated pathnames in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9…
- CVE-2026-97163 — Critical (CVSS 10.0): Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29
- CVE-2026-80155 — Critical (CVSS 10.0): Lantronix SLC8000 before firmware v9.7.0.5, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1,…
- CVE-2026-70200 — Critical (CVSS 10.0): Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an…
- CVE-2026-85706 — Critical (CVSS 10.0): GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9,…
- CVE-2026-76606 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2.