Follow Discord
Sweep 08 Oct 2026 · 18:53Z Build v2.1.295 516 read Stable v2.1.286 Latest v2.1.295 Next v2.1.295 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.280 ·

read_file Windows path-spoofing check now reports specific spelling categories

The Windows path-spoofing check run before reading files now names which trick it caught instead of a generic reason

Group of 2 You'll notice Improvements
JSON All of v2.1.280
You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
ElsewhereArea: what it touches
ImprovementsKind: in v2.1.280,
ImprovementsSection of the release

What

Before read_file touches the filesystem, it runs a check for suspicious Windows-style path spellings meant to spoof or bypass path checks. This check used to return one generic rejection reason; it now distinguishes seven specific tricks, each with its own message: NT device namespace, a colon appearing past the drive-letter position, tilde+digit short names, device-path prefixes, trailing dot or whitespace, DOS device-name suffixes, dot-run segments, and UNC/WebDAV-like forms.

The same change applies to permission checking for reading files under a trusted network directory: it now reports a suspicious_windows_spelling reason carrying the specific variant that triggered it, instead of one generic reason code.

Why

Knowing exactly which spelling trick tripped the check makes it much easier to understand why a file path was blocked, whether that's confirming a real security concern or diagnosing a false positive.

See this entry in the whole of v2.1.280 →

Feedback