Vulnerability intelligence
CVE-2026-39861 — Security Advisory
CVE-2026-39861 (CVSS 10.0): a symlink created inside the sandbox could point outside the workspace. When Claude Code's unsandboxed process followed it, arbitrary file writes landed anywhere on the host. Neither component could escape alone — their combination could.
CVSS 10.0
2026
What WebPulse reported · 2 analyses
Claude Code's Sandbox Had a Blind Spot: Symlinks That Crossed the Wall
CVE-2026-39861 (CVSS 10.0): a symlink created inside the sandbox could point outside the workspace. When Claude Code's unsandboxed process followed it, arbitrar
July 15, 2026
28 CVEs in Claude Code: AI Coding Tools as Attack Surface
Anthropic's Claude Code has accumulated 28 CVEs in its first year, including two CVSS 10.0 critical sandbox escapes. CVE-2026-46406, the latest, let any local u
July 4, 2026
Related vulnerabilities