{"version":"2.1.287","anchor":"hook-sandbox-temp-dir-selection-hardened","canonical_anchor":"hook-sandbox-temp-dir-selection-hardened","heading":"Remotely served project hooks pick a private temp folder more strictly","tier":"notice","area":"Hooks","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.287\/e\/hook-sandbox-temp-dir-selection-hardened","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.287","markdown":"### Remotely served project hooks pick a private temp folder more strictly\n\nProject hooks served remotely now use a temp folder only if it lies outside what the session can write, and log a specific error if none does\n\n**What**\n\nHooks are commands that run automatically at set points in a session. When project hooks are served remotely, they run in a sandbox, a restricted environment that limits what they can touch, and need a private temporary folder. Claude Code now looks for one in this order:\n\n- the folder named by `TMPDIR`\n\n- the system temp folder\n\n- on Linux, a fixed path\n\nThe chosen folder must lie outside anything the session can write to. Previously it used `TMPDIR` if that was out of reach, and otherwise fell back to a default temp folder. When no suitable folder is found, or the hook is not wrapped in the sandbox, Claude Code now logs an error with the specific reason, such as no temp directory lying outside what the session can write.\n\n**Why**\n\nThis tightens the sandbox around hooks that come from a remote source, so they cannot share a temp folder the session itself can write into. It applies only to remotely served hooks.\n\n- Area: Hooks\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 2\/5"}