CVE-2026-39861: Symlink Flaw in Claude Code Sandbox
A symlink flaw in Claude Code's sandbox allows escape from containment, potentially enabling code execution on the host. This vulnerability was referenced…
A symlink flaw in Claude Code's sandbox allows escape from containment, potentially enabling code execution on the host. This vulnerability was referenced…
Security researchers at Wiz have identified a critical vulnerability pattern, dubbed GhostApproval, affecting six popular AI coding assistants. The flaw allows a…
Two critical vulnerabilities in Cursor, an AI-powered code editor, allow prompt injection attacks to escape the editor's safety sandbox and execute arbitrary…
Cato AI Labs independently discovered the DuneSlide vulnerability, a symlink-based attack on AI coding assistants, which overlaps with the GhostApproval pattern and…
A vulnerability in Amazon Q Developer Language Server 1.69.0 and earlier allows malicious repositories to use symlinks to write to sensitive files…
A vulnerability in Cursor v3.0 and earlier allows malicious repositories to use symlinks to write to sensitive files outside the project directory,…