Vibe Coding
A Fourth Sandbox Escape Fix Lands in 2.1.224, Alongside JWT- and SigV4-Aware Credential Masking
2.1.224 fixed sandbox filesystem deny entries being bypassed on Linux and macOS — a fourth distinct sandbox/permission bypass across 2.1.221–2.1.224, after the zsh regex bypass, the PreToolUse auto-allow bypass, and the tabs/invisible-Unicode prompt bypass. The same release adds sandbox credential-masking options including JWT-aware masking and AWS SigV4, and fixes sandbox violation details not appearing in Bash results. The pattern is unambiguous: treat any Claude Code sandbox older than 2.1.224 as advisory, not as a boundary, and upgrade before running untrusted repos.
↳ Follow the thread