CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2026-39861: Symlink Flaw in Claude Code Sandbox

July 9, 2026

A symlink flaw in Claude Code's sandbox allows escape from containment, potentially enabling code execution on the host. This vulnerability was referenced in the Friendly Fire attack research.