Claude Code Symlink Flaw Exfiltrates Sensitive Files Without User Approval

Claude Code has a flaw in its startup memory loader related to handling symbolic links (symlinks) that can unintentionally expose readable files from outside a cloned repository, without requiring explicit user approval. The issue arises not from the tool following symlinks, something that is standard behavior in filesystems, but from a mismatch in how its […]

The post Claude Code Symlink Flaw Exfiltrates Sensitive Files Without User Approval appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

This article has been indexed from GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Read the original article: