Source Intelligence

DisclaimerUnofficial, and not affiliated with Anthropic. Nearly all of this is read straight out of what ships: npm bundles, captured prompts, published docs. Anthropic's own notes go in verbatim, marked as theirs. The rest is my reading, and every entry carries the strings behind it. If one looks wrong, vote it down and say why.

All of v2.0.37 Home All releases olderv2.0.36 v2.0.41newer
Claude Code v2.0.37

Windows Path Security Refinement

Simplified UNC Path Detection: The Windows UNC path detection was simplified from 8 security checks down to 1 basic pattern check. The new implementation removes specific checks for:

  • IPv4 address-based UNC paths (e.g., \\192.168.1.1\share)
  • IPv6 address-based UNC paths (e.g., \\[fe80::1]\share)
  • WebDAV DavWWWRoot patterns
  • SSL/port patterns like @SSL@8080

File operations no longer check for UNC paths at all, while bash command execution retains basic UNC path blocking. The security impact is reduced coverage for IP-based UNC paths and WebDAV-specific attacks.

Evidence

Old mB1() function at line 469909 (v2.0.36), new i2Q() function at line 222404, file path validation Cr2() at line 474880

Strings lifted out of the shipped bundle, so the claim above can be checked against them.

Related

Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.

See this entry in the whole of v2.0.37 →