CVE Explorer
CVE-2026-34452
The Claude SDK for Python provides access to the Claude API from Python applications. From version 0.86.0 to before version 0.87.0, the async local filesystem memory tool in the Anthropic Python SDK validated that model-supplied paths resolved inside the sandboxed memory directory, but then returned the unresolved path for subsequent file operations. A local attacker able to write to the memory directory could retarget a symlink between validation and use, causing reads or writes to escape the s
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-59","description":"CWE-59: Improper Link Resolution Before File Access ('Link Following')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:1576a082619d99b7835895676d245a121fe712c1925f9610461691d314d5a9bf · sha256:5583bf980f0e7b5f… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-367","description":"CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:1576a082619d99b7835895676d245a121fe712c1925f9610461691d314d5a9bf · sha256:5583bf980f0e7b5f… · /containers/cna/problemTypes/1/descriptions/0
Affected products and versions
1 source assertion{"product":"anthropic-sdk-python","vendor":"anthropics","versions":[{"status":"affected","version":">= 0.86.0, < 0.87.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:1576a082619d99b7835895676d245a121fe712c1925f9610461691d314d5a9bf · sha256:5583bf980f0e7b5f… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackRequirements":"NONE","attackVector":"LOCAL","baseScore":5.8,"baseSeverity":"MEDIUM","privilegesRequired":"LOW","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"LOW"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:1576a082619d99b7835895676d245a121fe712c1925f9610461691d314d5a9bf · sha256:5583bf980f0e7b5f… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
2 source assertions{"cweId":"CWE-59","description":"CWE-59: Improper Link Resolution Before File Access ('Link Following')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:1576a082619d99b7835895676d245a121fe712c1925f9610461691d314d5a9bf · sha256:5583bf980f0e7b5f… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-367","description":"CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:1576a082619d99b7835895676d245a121fe712c1925f9610461691d314d5a9bf · sha256:5583bf980f0e7b5f… · /containers/cna/problemTypes/1/descriptions/0
Source references
3 source assertions{"name":"https://github.com/anthropics/anthropic-sdk-python/commit/6599043eee6e86dce16953fcd1fd828052052be6","tags":["x_refsource_MISC"],"url":"https://github.com/anthropics/anthropic-sdk-python/commit/6599043eee6e86dce16953fcd1fd828052052be6"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:1576a082619d99b7835895676d245a121fe712c1925f9610461691d314d5a9bf · sha256:5583bf980f0e7b5f… · /containers/cna/references/1
{"name":"https://github.com/anthropics/anthropic-sdk-python/releases/tag/v0.87.0","tags":["x_refsource_MISC"],"url":"https://github.com/anthropics/anthropic-sdk-python/releases/tag/v0.87.0"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:1576a082619d99b7835895676d245a121fe712c1925f9610461691d314d5a9bf · sha256:5583bf980f0e7b5f… · /containers/cna/references/2
{"name":"https://github.com/anthropics/anthropic-sdk-python/security/advisories/GHSA-w828-4qhx-vxx3","tags":["x_refsource_CONFIRM"],"url":"https://github.com/anthropics/anthropic-sdk-python/security/advisories/GHSA-w828-4qhx-vxx3"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:1576a082619d99b7835895676d245a121fe712c1925f9610461691d314d5a9bf · sha256:5583bf980f0e7b5f… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.