Low severityNVD Advisory· Published Oct 3, 2025· Updated Oct 3, 2025
Claude Code: Permission deny bypass is possible through symlink
CVE-2025-59829
Description
Claude Code is an agentic coding tool. Versions below 1.0.120 failed to account for symlinks when checking permission deny rules. If a user explicitly denied Claude Code access to a file and Claude Code had access to a symlink pointing to that file, it was possible for Claude Code to access the file. Users on standard Claude Code auto-update will have received this fix automatically. Users performing manual updates are advised to update to the latest version. This issue is fixed in version 1.0.120.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@anthropic-ai/claude-codenpm | < 1.0.120 | 1.0.120 |
Affected products
2- Range: < 1.0.120
Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-66m2-gx93-v996ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-59829ghsaADVISORY
- github.com/anthropics/claude-code/security/advisories/GHSA-66m2-gx93-v996ghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.