Claude Code Symlink Import Lets Malicious Repositories Silently Exfiltrate Local Files

Claude Code can load files from outside a repository through a symlinked memory import, which may allow local data to be included in the model’s first outbound request before the model performs any actions. A recently reported Claude Code issue highlights a consent and provenance flaw in its memory import feature, rather than its expected […]

This article has been indexed from Cyber Security News

Read the original article: