Claude Code can load files from outside a repository through a symlinked memory import, which may allow local data to be included in the model’s first outbound request before the model performs any actions. A recently reported Claude Code issue highlights a consent and provenance flaw in its memory import feature, rather than its expected handling of filesystem symlinks. Instead, the tool checks whether an @import is within a project using its visible path, but it follows symlinks when reading the file. This difference allows a malicious repository to import a readable file from outside its directory without triggering Claude Code’s external import approval dialog. GitHub shows link as an in-repo symlink...
Les hele artikkelen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!