Skip to content
Vulnerability intelligence

CVE-2026-39861 — Security Advisory

CVE-2026-39861 (CVSS 10.0): a symlink created inside the sandbox could point outside the workspace. When Claude Code's unsandboxed process followed it, arbitrary file writes landed anywhere on the host. Neither component could escape alone — their combination could.

CVSS 10.0 2026