logo

Claude Code Symlink Import Lets Malicious Repositories Silently Exfiltrate Local Files

ID: a4beb328-11f5-5729-880a-b51d64053bc7

STIX ID: report--a4beb328-11f5-5729-880a-b51d64053bc7

Feed Name: cybersecurityNews.com

Threat Score
65/100

Date Published: 2026-07-27

Date Updated: 2026-07-27

Author: Abinaya

...
...

This report describes a canonicalization/symlink vulnerability in Claude Code's memory import feature: a repository can include an `@import` pointing to a symlinked file that appears in-repo but resolves to a local file (e.g., `/etc/passwd`), causing the file's contents to be loaded into the model's initial context and potentially exfiltrated (including to repository-configured endpoints) before any user approval.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.