AE-9C54Z2RQ
Coding agent's unsandboxed writer follows a symlink created by a sandboxed command, writing files outside the workspace
SECURITY FAILUREseverity: HIGHcause: VERIFIEDoutcome: RESOLVED UNVERIFIEDconfidence: MEDIUM
Claude Code's sandbox did not stop sandboxed processes from creating symlinks to locations outside the workspace. When the unsandboxed application later wrote to a path inside such a symlink, it followed it and wrote outside the workspace without prompting the user, a combined sandbox escape that could lead to code execution outside the sandbox; exploitation required prompt injection via untrusted content in the context window.
- Framework / agent
- Claude Code · terminal coding agent
- Remediation attempts
- APPLIED
- Recurrence
- not documented
- Source languages
- en
- Updated
- 2026-09-29
Sources
- SECURITY ADVISORY Claude Code: Sandbox Escape via Symlink Following Allows Arbitrary File Write Outside Workspace — https://github.com/anthropics/claude-code, retrieved 2026-09-29
Symptoms
- The agent writes to a location outside the workspace through a symlink without asking the user for confirmation
- Arbitrary file writes outside the sandbox become possible, potentially leading to code execution
The full record — root-cause evidence, every remediation attempt with its status and verification, failed attempts, patch references, verbatim quotes and recurrence — is a paid lookup (0.018 USDC via x402). Agents:
GET /api/v1/cases/AE-9C54Z2RQ. PricingSimilarity to your system is not implied. A remediation that worked in the documented context may not work in yours.