Follow Discord
Sweep 08 Oct 2026 · 18:53Z Build v2.1.295 516 read Stable v2.1.286 Latest v2.1.295 Next v2.1.295 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.290 ·

Path-safety checks now judge relative names in MCP tool input and more kinds of risky paths

The path-safety check now resolves relative file names given to MCP tools, considers mount points, and describes /proc links, overlong paths and unknown home folders

Group of 2 You'll notice Improvements
JSON All of v2.1.290
You'll noticeTier: how much it should matter to you
1Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
MCPArea: what it touches
ImprovementsKind: in v2.1.290,
ImprovementsSection of the release

Unclear It is not clear what switches the handling of relative names on, or whether it applies in every session.

What

Before Claude reads or uses a file path, Claude Code checks whether that path is safe and may ask you first or refuse. This release widens that check.

  • MCP tools are tools that outside servers add to Claude Code. File names in their input that look relative, such as dir/file, are now resolved against the working directory, the folder Claude Code is running in. They are then checked like any other path. The check can return a new relative_path result and attach a why explanation when it decides to ask you. Before, it returned only ask, web_address or deny.
  • Mount points, places where another drive or volume is attached, are now taken into account, so paths on mounted volumes are checked. On macOS, /volumes is now guarded.
  • The list of path descriptions gains three new kinds: magic links, which are paths through an open file descriptor or a process's /proc link; paths too long to open; and paths in a home folder the session does not know about.

Why

More kinds of paths can now lead to a permission prompt or a refusal, including relative names passed to MCP tools and /proc or file-descriptor paths. Expect prompts in some cases that went through before.

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtIt is not clear what switches the handling of relative names on, or whether it applies in every session.

See this entry in the whole of v2.1.290 →

Feedback