// ClaudeHIGH
Tego AI disclosed a vulnerability in Claude Code where symbolic link attacks via CLAUDE.md files can cause unauthorized file reads outside the project scope. The tool follows @import directives pointing to symbolic links without user approval or warnings, allowing attackers to exfiltrate sensitive files when a developer clones a malicious repository and invokes Claude Code. This is the second disclosed flaw in Claude's ecosystem within one week.
// Get alerts for Claude