Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3444 articles · 168093 vulns · 36/41 feeds (7d)
← Back to list
—
CVE-2026-46406PATCHED
anthropic · claude code

@anthropic-ai/claude-code has an Insecure Temporary File in /copy Command that Enables Response Disclosure and Symlink-Based File Write

Description

The Claude Code `/copy` command wrote responses to a hardcoded, predictable path (`/tmp/claude/response.md`) without UID isolation, randomness, or symlink protection. The file was created world-readable (0644) in a world-traversable directory (0755), allowing any local user to read a privileged user's Claude response, which could contain secrets or credentials. Additionally, because the path was static and predictable, a local attacker could pre-create the directory and plant a symlink at the expected file path, causing the privileged process to follow the symlink and overwrite an attacker-chosen file with the response text. Exploiting this required a local unprivileged user on the same system and a privileged user to run the `/copy` command. Users on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to the latest version. Claude Code thanks hackerone.com/c_h4ck_0 for reporting this issue.

Affected Products

VendorProductVersions
anthropicclaude codenpm/@anthropic-ai/claude-code: >= 2.1.59, < 2.1.128

References

  • https://github.com/advisories/GHSA-4vp2-6q8c-pvq2(advisory)
  • https://github.com/anthropics/claude-code/security/advisories/GHSA-4vp2-6q8c-pvq2
  • https://github.com/advisories/GHSA-4vp2-6q8c-pvq2
CISA KEV❌ No
Actively exploited❌ No
Patch available
@anthropic-ai/claude-code@2.1.128
CWECWE-59, CWE-200, CWE-377
PublishedJun 25, 2026
Tags
GHSA-4vp2-6q8c-pvq2npm
Trending Score0
Source articles0
Independent0
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-54316EXP
Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch
Trending: 23
HIGHCVE-2026-7574
Anthropic Claude Desktop Cowork VM Image Contents Not Validated Before Use
Trending: 19
PRE-CVE
Anthropic's Fable 5 Model Jailbroken
Trending: 10
HIGHCVE-2026-40068
Claude Code arbitrary code execution via git worktree commondir trust dialog bypass
NONECVE-2026-35022EXP
Anthropic Claude Code & Agent SDK OS Command Injection via Authentication Helper

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 25, 2026
Patch Available
Jun 25, 2026
Discovered by ZDM
Jun 25, 2026