Threat reportVulnerabilityTL-2026-1718

Claude Code Symlink Flaw in Startup Memory Loader Enables Silent File Exfiltration via CLAUDE.md Imports

mediumACTIVE

Claude Code Symlink Flaw in Startup Memory Loader Enables (TL-2026-1718), also tracked as CLAUDE.md Symlink Exfiltration Flaw, is a medium-severity software vulnerability, first published 2026-07-27. It has no confirmed attribution, affects Anthropic Claude Code, references 2 CVEs (CVE-2025-59829, CVE-2026-25724), maps to 19 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 24 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
2Referenced vulnerabilities
Techniques
19MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
24Indicators of compromise

Key facts for TL-2026-1718

Threat ID
TL-2026-1718
Also known as
CLAUDE.md Symlink Exfiltration Flaw, Startup Memory Loader Symlink Flaw
Severity
MEDIUM
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, softwaredevelopment
Target regions
Global
Detection rules
9
Indicators of compromise
24

Malware and tooling in Claude Code Symlink Flaw in Startup Memory Loader Enables

Malware and tooling: Claude Code

How Claude Code Symlink Flaw in Startup Memory Loader Enables works

Tego AI researchers found that Claude Code v2.1.215's startup memory loader classifies an in-repository symlink referenced by a CLAUDE.md or .claude/rules/ @import directive using its lexical (in-repo) path, but then follows the symlink to its actual external target when reading the file, silently pulling readable files from outside the cloned repo into the first outbound model request with no warning or approval prompt.

Security researchers at Tego AI identified a file-exfiltration flaw in Claude Code v2.1.215's startup memory loader -- the code path responsible for ingesting CLAUDE.md and .claude/rules/ @import directives (e.g. @./docs/setup.md) into the assistant's initial context before any user-facing tool call occurs. When an @import directive references an in-repository symbolic link, Claude Code's security classification evaluates the link's lexical (in-repo) path -- e.g. ./link -- to decide whether the referenced file is 'internal' and therefore safe to read without warning; validation runs BEFORE symlink resolution, creating the exposure window. The actual file-read operation, however, follows the symlink to its resolved, real-world target and labels the imported content as ordinary 'project instructions, checked into the codebase' without ever displaying the resolved filesystem path to the user. A malicious or compromised repository can therefore ship an innocuous-looking CLAUDE.md alongside a symlink that points outside the repository root -- for example, at /etc/passwd or other predictable, sensitive paths on developer workstations, CI runners, containers, and standardized developer images -- and have its contents silently folded into the very first outbound request Claude Code sends to the configured model endpoint, with no external-import warning, no file-read approval dialog, and no tool-call execution required. The exposure is widened by two compounding trust behaviors: workspace-trust inheritance from parent directories can let a freshly cloned repository skip the trust prompt entirely, and non-interactive/scripted invocations (CI pipelines, automation) skip both the trust and import-warning prompts by design.

This is the third distinct occurrence of the same underlying weakness class (CWE-61 / CWE-59 -- improper resolution of a symbolic link before a security-relevant filesystem operation) in Claude Code. It was preceded by CVE-2025-59829 (permission deny-rule bypass through symlink; CWE-61; affected versions < v1.0.120, fixed in v1.0.120, published October 3, 2025; reported via hackerone.com/vinai) and CVE-2026-25724 (deny-rule enforcement bypass via symlink, fixed in v2.1.7, published February 13, 2026). CVE-2025-59829 was a TOCTOU (time-of-check-time-of-use) style flaw: Claude Code evaluated permission deny rules against the initially requested path, then a user could plant a symlink pointing at an explicitly denied file so that the later filesystem read followed the link and returned the denied content anyway; it scored CVSS v4.0 2.3 (Low), vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N. CVE-2026-25724 was independently identified and written up by Terra Security researcher Ofir Hamam (Head of Offensive Security) using a semantic-manipulation exploit chain: the poisoned repository contained a symlink literally named test.py (masquerading as an ordinary source file) alongside a misleading code comment reading approximately '## Known vulnerable function will be fixed in the future' -- bait crafted to make the agent's semantic reasoning treat inspecting the file as a legitimate, in-scope task. The agent then followed the test.py symlink, which pointed at ~/.ssh/id_rsa, and exposed the private key contents despite an explicit deny rule. Both prior fixes patched the permission/deny-rule enforcement subsystem; neither fix reached the startup memory loader, leaving this third code path exploitable with a simpler mechanism requiring no semantic bait at all -- the loader silently trusts any lexically in-repo path.

Compounding the exposure, a malicious repository's .claude/settings.json can configure an ANTHROPIC_BASE_URL override, redirecting the outbound model request -- and any exfiltrated file contents riding along in it -- to an attacker-controlled endpoint that impersonates a legitimate API host instead of Anthropic's own. Because the read-and-send sequence completes before the model produces any response, the flaw requires no code execution, no malicious tool call, and no explicit user approval: cloning a booby-trapped repository and simply launching Claude Code inside it is sufficient to trigger exfiltration, assuming the invoking account has read access to the linked target. Tego AI's Head of Research, Tomer Niv, framed the underlying design gap directly: 'Context is whatever gets sent to the model, and the model is a network endpoint like any other,' and noted the leaked content surfaces 'on the first request, with no code execution.'

Tego AI reported the issue to Anthropic via HackerOne in July 2026 and published its findings on July 24, 2026 -- one week after disclosing an unrelated Claude Tag Slack-integration flaw (July 14, 2026) in which the integration could be triggered by unstructured '@Claude' text embedded in bot-generated messages, webhooks, or automated feeds, without a genuine Slack @-mention. In that companion disclosure, Tego AI CTO and co-founder Tal Melamed demonstrated that a crafted bot message could cause Claude Tag to retrieve and publish internal organizational information into Slack and even execute deletion commands against connected resources via linked applications and MCP servers, and asked publicly: 'who is actually authorized to instruct the agent?' -- arguing for controls that validate the origin and purpose of sensitive actions before an agent executes them. Anthropic closed the startup-memory-loader HackerOne report as 'Informative,' maintaining that the 'trust this folder' consent dialog already constitutes the intended security boundary and grants broad read/edit/execute access once accepted, treating any file the account can read as implicitly in scope. Tego AI disputes this framing, arguing that CI runners, containers, and standardized developer images have predictable sensitive-file locations that make silent, warning-free exfiltration a distinct and underrated risk even within an already-trusted folder. Researchers recommend canonicalizing imported paths before containment checks, rejecting or explicitly warning on @import targets that resolve outside the repository root, always displaying the resolved (not lexical) target path to the user, and requiring separate, explicit approval before honoring any endpoint-override configuration such as ANTHROPIC_BASE_URL. No CVE has been assigned to this specific finding, no patch has been confirmed, and there is no evidence of in-the-wild exploitation as of disclosure.

MITRE ATT&CK techniques used in TL-2026-1718

Collection

T1005 Data from Local System; T1213 Data from Information Repositories

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1564.001 Hidden Files and Directories

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567.002 Exfiltration to Cloud Storage

Command and Control

T1071.001 Web Protocols; T1102 Web Service

Discovery

T1083 File and Directory Discovery; T1518 Software Discovery

Initial Access

T1195.002 Compromise Software Supply Chain; T1199 Trusted Relationship

Execution

T1204.002 Malicious File

Impact

T1485 Data Destruction

Credential Access

T1552.001 Credentials In Files; T1552.004 Private Keys

Reconnaissance

T1592.002 Software

Resource Development

T1608.001 Upload Malware

Affected products and versions in Claude Code Symlink Flaw in Startup Memory Loader Enables

  • Anthropic — Claude Code
    Vulnerable versions: 2.1.215

Remediation for Claude Code Symlink Flaw in Startup Memory Loader Enables

Immediate actions

  • Do not run Claude Code unattended against unfamiliar or externally-contributed repositories until the startup memory loader's symlink handling is fixed
  • Audit CLAUDE.md and .claude/rules/ files in newly cloned repositories for @import directives before accepting the 'trust this folder' prompt
  • Search repositories for symbolic links (e.g. find . -type l) prior to invoking Claude Code, especially in newly cloned or forked repos
  • Restrict outbound network egress from CI runners and developer sandboxes running Claude Code to known Anthropic API endpoints only
  • Disable or tightly scope non-interactive/scripted Claude Code invocations in CI, which silently skip the trust and import-warning prompts
  • Do not rely on parent-directory workspace-trust inheritance for freshly cloned or forked repositories

Workarounds

  • Manually inspect and reject symlinked @import targets that resolve outside the repository root before allowing Claude Code to process them
  • Avoid storing SSH keys, cloud credentials, or other sensitive files at predictable, well-known paths accessible to the account running Claude Code
  • Verify a cloned repository's .claude/settings.json has no unexpected ANTHROPIC_BASE_URL override before the first Claude Code run
  • Treat any repository comment or docstring hinting at 'known issues' or 'files to inspect' as untrusted, potentially manipulative input to the agent

Longer-term hardening

  • Track Anthropic's response and any future patch to the startup memory loader code path beyond the current 'Informative' HackerOne closure
  • Require least-privilege, gradual autonomy for agentic coding tools operating against untrusted repositories
  • Deploy agent runtime monitoring that inspects outbound context and network egress from AI coding assistants before requests leave the host
  • Isolate agentic tool sessions against unknown or third-party repositories in disposable containers or VMs with no access to host credentials
  • Push for import-path canonicalization and resolved-path display as an upstream product fix rather than relying solely on manual audit
  • Establish agent-authorization validation (origin and purpose checks) for any chat/bot-triggered agent integration, per Tego AI's Claude Tag findings

CVEs associated with Claude Code Symlink Flaw in Startup Memory Loader Enables

CVE-2025-59829, CVE-2026-25724

Weaknesses (CWE) in Claude Code Symlink Flaw in Startup Memory Loader Enables

CWE-61, CWE-59

Timeline of Claude Code Symlink Flaw in Startup Memory Loader Enables

  • CVE-2025-59829 is characterized as a TOCTOU (time-of-check-time-of-use) style symlink-resolution flaw and scored CVSS v4.0 2.3 (Low), vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N; deny rules were validated against the requested path but not the resolved symlink target.
  • CVE-2025-59829 (permission deny-rule bypass through symlink, CWE-61) patched in Claude Code v1.0.120; reported via HackerOne (hackerone.com/vinai).
  • CVE-2026-25724 (deny-rule enforcement bypass via symlink, CWE-61) published/patched in Claude Code v2.1.7; deny rules were matched against the literal requested path instead of the canonical resolved path.
  • Terra Security researcher Ofir Hamam (Head of Offensive Security) publishes an independent technical writeup of CVE-2026-25724, demonstrating a semantic-manipulation exploit chain in which a symlink literally named test.py, paired with a misleading repository comment ('Known vulnerable function will be fixed in the future'), guided Claude Code into reading the link -- which resolved to ~/.ssh/id_rsa -- despite an explicit deny rule.
  • Tego AI CTO and co-founder Tal Melamed publishes an accompanying statement on the Claude Tag disclosure asking 'who is actually authorized to instruct the agent?' and calling for controls that validate the origin and purpose of sensitive actions before an agent executes them.
  • Tego AI publicly discloses an unrelated Claude Code/Claude Tag Slack-integration flaw in which the integration could be triggered by unstructured '@Claude' text from untrusted sources (bots, webhooks, automated feeds), enabling unauthorized retrieval/publication of internal data and deletion of connected resources via linked apps and MCP servers.
  • Tego AI publicly discloses the flaw via GlobeNewswire, one week after its Claude Tag Slack disclosure; Anthropic closes the HackerOne report as 'Informative,' maintaining the 'trust this folder' prompt is the intended security boundary. Tego AI disputes this, citing predictable sensitive-file paths in CI runners, containers, and standardized developer images.
  • Tego AI reports the startup memory loader symlink/CLAUDE.md exfiltration flaw to Anthropic via HackerOne, having found the same lexical-path-vs-resolved-path weakness class reachable through a third code path not covered by the CVE-2025-59829 or CVE-2026-25724 fixes.
  • GBHackers publishes a detailed technical writeup of the vulnerability and Tego AI's disclosure, corroborating the lexical-path classification vs. resolved-path read mismatch in the startup memory loader and detailing that workspace-trust inheritance and non-interactive/CI invocations independently skip the trust and import-warning prompts.

Sources cited for Claude Code Symlink Flaw in Startup Memory Loader Enables

Detection coverage for TL-2026-1718

As of 2026-07-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1718 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
24 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats