What
The sandbox can limit which websites commands run by Claude may reach. Its network proxy, the go-between that forwards those connections, now also checks the IP addresses an allowed hostname actually resolves to, not just the name.
- Built-in check: a hostname that resolves only to loopback, unspecified, link-local, multicast, broadcast or cloud-metadata addresses (for example
100.100.100.200,168.63.129.16,fd00:ec2::/32), or to this machine's own addresses, is refused with the errorERR_SRT_RESOLVED_ADDRESS_DENIED. The proxy answers with HTTP 403 and the headerX-Proxy-Error: blocked-by-sandbox-runtime. - Exception: such an address can still be reached when its IP literal is itself listed in
allowedDomains. - New setting
deniedResolvedAddresses: extra IP addresses or CIDR ranges (IPv4 or IPv6, unbracketed) that an allowed hostname must not resolve to, checked alongside the built-in set. A name that resolves only into them is refused as "a listed address". - Bad entries are rejected with "Invalid IP address or CIDR range. Use an IPv4/IPv6 literal or CIDR ...".
- The settings schema says this check is not applied to connections routed through
parentProxyormitmProxy.
Why
Without this, an allowed domain whose DNS answer points at an internal address, such as a cloud metadata service, could be used to reach that address from inside the sandbox. Administrators can now add their own internal ranges to the refused set. A command that relied on an allowed name resolving to a local or internal address will now be refused unless that IP is itself allowed.
Whether this setting can be set in the sandbox section of settings.json, rather than only inside the sandbox's own configuration, is not…