{"version":"2.1.285","anchor":"git-remote-url-parsing-hardened-against-host-confusion-trick","canonical_anchor":"git-remote-url-parsing-hardened-against-host-confusion-trick","heading":"Stricter checks on git remote URLs","tier":"notice","area":"Git","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.285\/e\/git-remote-url-parsing-hardened-against-host-confusion-trick","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.285","markdown":"### Stricter checks on git remote URLs\n\nGit remote URLs with bracketed hosts, encoded null characters or ambiguous hosts are now rejected when Claude Code matches repositories\n\n**Unclear.** Which Claude Code features rely on this repository matching is not stated.\n\n**What**\n\nA git remote URL is the address a repository is pushed to and pulled from. Claude Code reads these addresses to work out which repository you are in and to check them against allowed lists. That reading is now stricter. A remote URL is rejected when it has:\n\n- a host written in square brackets\n\n- a percent-encoded null character (`%00`) or a raw null character\n\n- a host that different URL readers would interpret differently\n\n**Why**\n\nThese are known tricks for making one address look like another, so the stricter checks make repository matching harder to fool. A remote with an unusual address that worked before may now be refused.\n\n- Area: Git\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5"}