{"version":"2.1.277","anchor":"agent-memory-now-refuses-to-read-through-symlinks-leaving-th","canonical_anchor":"agent-memory-entrypoint-hardened-against-symlink-escapes","heading":"Agent memory reads are now protected against symlink escapes","tier":"notice","area":"Memory","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.277\/e\/agent-memory-now-refuses-to-read-through-symlinks-leaving-th","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.277","markdown":"### Agent memory reads are now protected against symlink escapes\n\nClaude Code now refuses to read an agent memory file or directory if it's a symlink pointing outside the project, logging a skip event instead\n\n**What**\n\nAgent memory (the `MEMORY.md` entrypoint and its directory) is now checked before being read:\n\n- If the entrypoint is a symlink or another special file rather than a regular file, it's refused\n\n- If the entrypoint or its directory resolves outside the working copy, or through a dangling or otherwise unresolvable link, it's refused too\n\nIn all these cases, Claude Code skips the read and logs a telemetry event instead of silently following the link.\n\n**Why**\n\nWithout this check, a symlink inside the working copy could point to files elsewhere on disk, letting memory reads escape the project directory. This closes that path while keeping normal, in-project memory files working as before.\n\n- Area: Memory\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5"}