{"version":"2.1.284","anchor":"sandbox-allowed-domains-check-now-catches-bracketed-loopback","canonical_anchor":"sandbox-allowed-domains-check-now-catches-bracketed-loopback","heading":"Bash network allow list now catches bracketed loopback addresses","tier":"notice","area":"Permissions","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284\/e\/sandbox-allowed-domains-check-now-catches-bracketed-loopback","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284","markdown":"### Bash network allow list now catches bracketed loopback addresses\n\nThe Bash tool's per-command allowed_domains check now also rejects disguised loopback or IPv4 addresses written inside square brackets\n\n**Unclear.** Exactly which bracketed addresses got past the check before is not settled.\n\n**What**\n\nIn auto mode, the Bash tool can take an `allowed_domains` list for a single command, naming the hosts that command may reach over the network. Claude Code already rejected entries that write a loopback address (your own machine) or an IPv4 host in a disguised form, such as an IPv4-mapped or NAT64 IPv6 address. That check now also looks inside a leading pair of square brackets. Bracketed forms, including ones with a port number, can no longer get past it. The error still tells you to allow the plain dotted IPv4 address or the real host name instead.\n\n**Why**\n\nIn auto mode Claude supplies the host list itself, so this closes a way around the sandbox's network check. The sandbox is the walled-off environment that commands run in.\n\n- Area: Permissions\n- Names: `allowed_domains`\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5"}