{"id":"CVE-2025-59829","summary":"Claude Code: Permission deny bypass is possible through symlink","details":"Claude Code is an agentic coding tool. Versions below 1.0.120 failed to account for symlinks when checking permission deny rules. If a user explicitly denied Claude Code access to a file and Claude Code had access to a symlink pointing to that file, it was possible for Claude Code to access the file. Users on standard Claude Code auto-update will have received this fix automatically. Users performing manual updates are advised to update to the latest version. This issue is fixed in version 1.0.120.","aliases":["GHSA-66m2-gx93-v996"],"modified":"2026-04-10T05:32:13.403500Z","published":"2025-10-03T20:03:02.999Z","database_specific":{"cwe_ids":["CWE-61"],"cna_assigner":"GitHub_M","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/59xxx/CVE-2025-59829.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/59xxx/CVE-2025-59829.json"},{"type":"ADVISORY","url":"https://github.com/anthropics/claude-code/security/advisories/GHSA-66m2-gx93-v996"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-59829"}],"affected":[{"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-59829.json","unresolved_ranges":[{"events":[{"introduced":"0"},{"fixed":"1.0.120"}]}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"}]}