Follow Discord
Sweep 25 Sep 2026 · 19:33Z Build v2.1.283 504 read Stable v2.1.274 Latest v2.1.283 Next v2.1.283 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.281 ·

Sandboxed Bash: allow-read dropping handles unvetted path expansions

Sandboxed Bash now drops read permissions for paths it cannot fully check, and reports a missing working directory by name

You'll notice Improvements
JSON All of v2.1.281
You'll noticeTier: how much it should matter to you
1Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
SandboxArea: what it touches
ImprovementsKind: in v2.1.281,
ImprovementsSection of the release
What

When Claude runs shell commands in a sandbox (a restricted space that limits which files a command can reach), some folders are allowed to be read. The sandbox now removes an allowed-read entry when it cannot check how that entry's path expands, for example a path containing a variable or wildcard. More entries are dropped as a result, and the sandbox refuses access rather than allowing it when in doubt.

A new MissingWorkingDirectoryError reports Path "…" does not exist when the working directory is missing. A helper to fix the working directory in place was also added.

Why

A path that cannot be checked no longer opens up reading by accident. Watch for commands that could read a folder before and are now refused because its allowed-read entry was dropped.

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtThe finding does not say exactly which path expansions count as checked ("vetted").

See this entry in the whole of v2.1.281 →

Feedback