Files another session sends you are size- and hash-checked and confined to a staging folder before use.
Attachment verification runs only when peer messaging is enabled, which is off by default.
What's wrong with this entry?
When another session sends file attachments, they are now checked before Claude sees them: the attachment list is schema-parsed and capped in count, each path must sit inside the transfer staging directory, must be a regular file, and must match the declared size and hash. Verified files are copied into an uploads directory with owner-only permissions. This runs only with peer messaging enabled.
- A file that fails any check is logged with a
[peer-file-transfer]prefix and surfaces as a notice, rather than being attached silently.
transfer path is outside the file-transfer spool
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.234
Messages injected by a host are classified separately from peer messages
Both mention cross
-
v2.1.234
Cross-session control requests check ids more carefully
Both mention cross
-
v2.1.234
Notice acks now wait for the record to persist
Both mention cross