Claude Code 2.1.233 Closes an NTLM Credential-Leak Vector via NT `\??\` Device-Prefixed Windows Paths
Claude Code Changelog·medium signal
Buried in the 2.1.233 changelog is a real security fix: Windows paths spelled with the NT device prefix `\??\` bypassed Claude Code's UNC path validation, meaning a crafted path could reach a remote SMB host and leak NTLM credentials on connect. The same release also fixed skill/command argument substitution so argument values are no longer re-expanded as template markers — a second injection-shaped bug in the skills layer. Windows users on 2.1.232 or earlier should upgrade; this is not a cosmetic patch.