Vibe Coding
Claude Code's Workflow Tool Was Reading a scriptPath Outside the Session's Permitted Scope Before the Permission Check
2.1.251 fixes the Workflow tool reading, and quoting in error messages, a `scriptPath` outside what the session may read before the permission check ran. The release also rejects plugin commands declared in a marketplace entry that point outside the plugin directory, now with an explicit path-traversal error. Error-message echo is the sharp edge here: a failed read still leaked file contents into the transcript.
↳ Follow the thread