Filenames and MCP content types are escaped in the transcript, closing a text-injection route.
What's wrong with this entry?
The message recorded when you open a file in the IDE now escapes the filename, and the content type reported by an MCP server for binary results is escaped before being shown as [Binary content: …]. This narrows a path by which a crafted filename or server-supplied metadata could inject text into the conversation.
The user opened the file
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.222
Messages from other sessions get a sanitized sender label
Both mention transcript
-
v2.1.222
Blank message summaries are ignored
Both mention transcript
-
v2.1.236
Batch tool calls survive a history replay intact
Both mention transcript