CVE-2026-25724 | Anthropic claude-code up to 2.1.6 Setting settings.json symlink (GHSA-4q92-rfm6-2cqx / Nessus ID 305984)
A vulnerability was found in Anthropic claude-code up to 2.1.6 and classified as critical. This affects an unknown function of the file settings.json of the component Setting Handler. Such manipulation leads to symlink following.
This vulnerability is documented as CVE-2026-25724. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.