Vibe Coding
Claude Code 2.1.233 Patches a Windows NT `\??\` Device-Prefix Escape That Bypassed UNC Path Validation
Released August 15, v2.1.233 fixes Windows paths written with the NT device prefix `\??\` slipping past Claude Code's UNC path validation — the third distinct Windows path/permission escape patched in eight days, after the Git Bash Cygwin-symlink bypass and the PowerShell variable-writing parameter bypass in 2.1.232. The same release also stops nested git repositories from inheriting trust from a parent directory. If you run Claude Code on Windows with any allowlist-based permission config, treat pre-2.1.233 as leaky.
↳ Follow the thread