{"version":"2.1.288","anchor":"plugin-uninstall-reads-settings-via-safer-path-vetting","canonical_anchor":"plugin-uninstall-reads-settings-via-safer-path-vetting","heading":"Plugin uninstall checks the settings file more carefully before reading it","tier":"notice","area":"Plugins","scope":"individual","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.288\/e\/plugin-uninstall-reads-settings-via-safer-path-vetting","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.288","markdown":"### Plugin uninstall checks the settings file more carefully before reading it\n\nUninstalling a plugin now checks links and symlinks before reading the settings file, and reports why it refused to read one\n\n**Unclear.** It is not clear what a user sees when a settings file is refused, beyond the logged message.\n\n**What**\n\nWhen you uninstall a plugin, Claude Code reads a settings file to see whether the plugin is enabled. That read now checks the file's path for links and symlinks first. A symlink is a file that points to another file somewhere else. If the path looks unsafe, Claude Code skips the file and logs a message saying it was not read, with a short reason such as `suspect-link` or `crossing`.\n\nBefore this change, the only check was for network paths, and the file was then read directly.\n\n**Why**\n\nThis makes it harder for a planted symlink to make Claude Code read a file it should not read during an uninstall.\n\n- Area: Plugins\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5\n- Scope: individual\n- Heads-up: no"}