# Claude Code Symlink Flaw in Startup Memory Loader Enables Silent File Exfiltration via CLAUDE.md Imports

> Tego AI researchers found that Claude Code v2.1.215's startup memory loader classifies an in-repository symlink referenced by a CLAUDE.md or .claude/rules/ @import directive using its lexical (in-repo) path, but then follows the symlink to its actual external target when reading the file, silently pulling readable files from outside the cloned repo into the first outbound model request with no warning or approval prompt.

- **Published:** 2026-07-27T00:00:00Z
- **Last reviewed:** 2026-07-27T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1718
- **ID:** TL-2026-1718
- **Severity:** MEDIUM
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 24 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2025-59829, CVE-2026-25724

## Description

Security researchers at Tego AI identified a file-exfiltration flaw in Claude Code v2.1.215's startup memory loader -- the code path responsible for ingesting CLAUDE.md and .claude/rules/ @import directives (e.g. @./docs/setup.md) into the assistant's initial context before any user-facing tool call occurs. When an @import directive references an in-repository symbolic link, Claude Code's security classification evaluates the link's lexical (in-repo) path -- e.g. ./link -- to decide whether the referenced file is 'internal' and therefore safe to read without warning; validation runs BEFORE symlink resolution, creating the exposure window. The actual file-read operation, however, follows the symlink to its resolved, real-world target and labels the imported content as ordinary 'project instructions, checked into the codebase' without ever displaying the resolved filesystem path to the user. A malicious or compromised repository can therefore ship an innocuous-looking CLAUDE.md alongside a symlink that points outside the repository root -- for example, at /etc/passwd or other predictable, sensitive paths on developer workstations, CI runners, containers, and standardized developer images -- and have its contents silently folded into the very first outbound request Claude Code sends to the configured model endpoint, with no external-import warning, no file-read approval dialog, and no tool-call execution required. The exposure is widened by two compounding trust behaviors: workspace-trust inheritance from parent directories can let a freshly cloned repository skip the trust prompt entirely, and non-interactive/scripted invocations (CI pipelines, automation) skip both the trust and import-warning prompts by design.

This is the third distinct occurrence of the same underlying weakness class (CWE-61 / CWE-59 -- improper resolution of a symbolic link before a security-relevant filesystem operation) in Claude Code. It was preceded by CVE-2025-59829 (permission deny-rule bypass through symlink; CWE-61; affected versions < v1.0.120, fixed in v1.0.120, published October 3, 2025; reported via hackerone.com/vinai) and CVE-2026-25724 (deny-rule enforcement bypass via symlink, fixed in v2.1.7, published February 13, 2026). CVE-2025-59829 was a TOCTOU (time-of-check-time-of-use) style flaw: Claude Code evaluated permission deny rules against the initially requested path, then a user could plant a symlink pointing at an explicitly denied file so that the later filesystem read followed the link and returned the denied content anyway; it scored CVSS v4.0 2.3 (Low), vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N. CVE-2026-25724 was independently identified and written up by Terra Security researcher Ofir Hamam (Head of Offensive Security) using a semantic-manipulation exploit chain: the poisoned repository contained a symlink literally named test.py (masquerading as an ordinary source file) alongside a misleading code comment reading approximately '## Known vulnerable function will be fixed in the future' -- bait crafted to make the agent's semantic reasoning treat inspecting the file as a legitimate, in-scope task. The agent then followed the test.py symlink, which pointed at ~/.ssh/id_rsa, and exposed the private key contents despite an explicit deny rule. Both prior fixes patched the permission/deny-rule enforcement subsystem; neither fix reached the startup memory loader, leaving this third code path exploitable with a simpler mechanism requiring no semantic bait at all -- the loader silently trusts any lexically in-repo path.

Compounding the exposure, a malicious repository's .claude/settings.json can configure an ANTHROPIC_BASE_URL override, redirecting the outbound model request -- and any exfiltrated file contents riding along in it -- to an attacker-controlled endpoint that impersonates a legitimate API host instead of Anthropic's own. Because the read-and-send sequence completes before the model produces any response, the flaw requires no code execution, no malicious tool call, and no explicit user approval: cloning a booby-trapped repository and simply launching Claude Code inside it is sufficient to trigger exfiltration, assuming the invoking account has read access to the linked target. Tego AI's Head of Research, Tomer Niv, framed the underlying design gap directly: 'Context is whatever gets sent to the model, and the model is a network endpoint like any other,' and noted the leaked content surfaces 'on the first request, with no code execution.'

Tego AI reported the issue to Anthropic via HackerOne in July 2026 and published its findings on July 24, 2026 -- one week after disclosing an unrelated Claude Tag Slack-integration flaw (July 14, 2026) in which the integration could be triggered by unstructured '@Claude' text embedded in bot-generated messages, webhooks, or automated feeds, without a genuine Slack @-mention. In that companion disclosure, Tego AI CTO and co-founder Tal Melamed demonstrated that a crafted bot message could cause Claude Tag to retrieve and publish internal organizational information into Slack and even execute deletion commands against connected resources via linked applications and MCP servers, and asked publicly: 'who is actually authorized to instruct the agent?' -- arguing for controls that validate the origin and purpose of sensitive actions before an agent executes them. Anthropic closed the startup-memory-loader HackerOne report as 'Informative,' maintaining that the 'trust this folder' consent dialog already constitutes the intended security boundary and grants broad read/edit/execute access once accepted, treating any file the account can read as implicitly in scope. Tego AI disputes this framing, arguing that CI runners, containers, and standardized developer images have predictable sensitive-file locations that make silent, warning-free exfiltration a distinct and underrated risk even within an already-trusted folder. Researchers recommend canonicalizing imported paths before containment checks, rejecting or explicitly warning on @import targets that resolve outside the repository root, always displaying the resolved (not lexical) target path to the user, and requiring separate, explicit approval before honoring any endpoint-override configuration such as ANTHROPIC_BASE_URL. No CVE has been assigned to this specific finding, no patch has been confirmed, and there is no evidence of in-the-wild exploitation as of disclosure.

## MITRE ATT&CK

- T1592.002 Software
- T1608.001 Upload Malware
- T1195.002 Compromise Software Supply Chain
- T1199 Trusted Relationship
- T1204.002 Malicious File
- T1027 Obfuscated Files or Information
- T1564.001 Hidden Files and Directories
- T1036 Masquerading
- T1083 File and Directory Discovery
- T1518 Software Discovery
- T1552.001 Credentials In Files
- T1552.004 Private Keys
- T1005 Data from Local System
- T1213 Data from Information Repositories
- T1041 Exfiltration Over C2 Channel
- T1567.002 Exfiltration to Cloud Storage
- T1071.001 Web Protocols
- T1102 Web Service
- T1485 Data Destruction

## Sources

- [Claude Code Symlink Flaw Exfiltrates Sensitive Files Without User Approval](https://gbhackers.com/claude-code-symlink-flaw-exfiltrates-sensitive-files/)
- [Tego AI Discloses Second Claude Flaw in a Week: Hidden Link Silently Sends Files to Attackers](https://www.globenewswire.com/news-release/2026/07/24/3332824/0/en/Tego-AI-Discloses-Second-Claude-Flaw-in-a-Week-Hidden-Link-Silently-Sends-Files-to-Attackers.html)
- [Tego AI Discloses Second Claude Flaw in a Week: Hidden Link Silently Sends Files to Attackers](https://hackread.com/tego-ai-discloses-second-claude-flaw-in-a-week-hidden-link-silently-sends-files-to-attackers/)
- [Claude Code Symlink Flaw Could Exfiltrate Files via CLAUDE.md Imports](https://mallory.ai/stories/019f9406-3e35-70ae-b440-2cf394a0b176)
- [Tego AI Finds Claude Tag Slack Integration Can Trigger Unauthorized Enterprise Actions](https://www.globenewswire.com/news-release/2026/07/14/3327209/0/en/Tego-AI-Finds-Claude-Tag-Slack-Integration-Can-Trigger-Unauthorized-Enterprise-Actions.html)
- [Tego AI Finds Claude Tag Slack Integration Can Trigger Unauthorized Enterprise Actions](https://hackread.com/tego-ai-finds-claude-tag-slack-integration-can-trigger-unauthorized-enterprise-actions/)
- [Claude Code permission deny bypass through symlink (GHSA-66m2-gx93-v996 / CVE-2025-59829)](https://github.com/anthropics/claude-code/security/advisories/GHSA-66m2-gx93-v996)
- [NVD - CVE-2025-59829](https://nvd.nist.gov/vuln/detail/CVE-2025-59829)
- [CVE Record: CVE-2025-59829](https://www.cve.org/CVERecord?id=CVE-2025-59829)
- [UNIX Symbolic Link (Symlink) Following in @anthropic-ai/claude-code (CVE-2025-59829)](https://security.snyk.io/vuln/SNYK-JS-ANTHROPICAICLAUDECODE-13299550)
- [CVE-2026-25724: Anthropic Claude Code Path Traversal](https://www.sentinelone.com/vulnerability-database/cve-2026-25724/)
- [UNIX Symbolic Link (Symlink) Following in @anthropic-ai/claude-code (CVE-2026-25724)](https://security.snyk.io/vuln/SNYK-JS-ANTHROPICAICLAUDECODE-15248353)
- [When AI Becomes the Attack Surface: Lessons from Discovering CVE-2026-25724](https://www.terra.security/blog/when-ai-becomes-the-attack-surface-lessons-from-discovering-cve-2026-25724)
- [CVE-2026-25724 : Claude Code is an agentic coding tool. Prior to version 2.1.7, Claude Code failed to strictly enforce deny rules](https://www.cvedetails.com/cve/CVE-2026-25724/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1718
