Crypto Ticker:
sysadmin from Cyber Security News

Claude Code Symlink Import Lets Malicious Repositories Silently Exfiltrate Local Files

Abinaya
3 hours ago
4 Views
0 Comments
Claude Code Symlink Import Lets Malicious Repositories Silently Exfiltrate Local Files

Claude Code can load files from outside a repository through a symlinked memory import, which may allow local data to be included in the model’s first outbound request before the model performs any actions. A recently reported Claude Code issue highlights a consent and provenance flaw in its memory import feature, rather than its expected handling of filesystem symlinks. Instead, the tool checks whether an @import is within a project using its visible path, but it follows symlinks when reading the file. This difference allows a malicious repository to import a readable file from outside its directory without triggering Claude Code’s external import approval dialog. GitHub shows link as an in-repo symlink...

Read the full article at the source.

Join the discussion — comment, vote, and submit links.

Register
Was this helpful?
Share:

Comments (0)

Please login or register to join the discussion

No comments yet. Be the first to comment!