Under the hoodTier: how much it should matter to you
1Useful: my rating, 1 to 5
0Signal: worth watching, 1 to 5
File AccessArea: what it touches
Internal ChangesKind: in v2.1.281,
Internal ChangesSection of the release
What
A null byte is an invisible "empty" character that should never appear inside a file path. Claude Code already refused such paths when it worked out where a file is. Now there is a single shared check that raises a specific error named NullBytePathError, and three places use it:
the code that works out a file's location
two parts of the code that tidy up file paths inside permission rules (the rules that say which files Claude Code may touch)
There is also a new variant of the check that quietly returns nothing instead of raising an error.
Why
Before this change, only the file-location code checked for null bytes. Now the permission-rule path handling also refuses these malformed paths, and they all produce one clearly named error.