
Claude Code patches symlink sandbox escape enabling arbitrary file writes
A GitHub advisory reports a High sandbox escape in `@anthropic-ai/claude-code` <2.1.64 where symlink writes can reach outside the workspace, enabling code execution via prompt injection.






