Security issues on Linux
Issues the maintainers labelled both platform:linux and area:security.
752 issues · 249 open · 503 resolved (67%) · first seen May 20, 2025
Is this getting better or worse?
This class of problem is still growing. 581 new reports in the last 90 days vs 45 in the 90 before — +1191%. The open backlog peaked at 381 in 2026-07 and sits at 249 today.
Derived by counting each matching issue from its creation date until it closed. First-party
computation over the anthropics/claude-code tracker — the trend is not published
anywhere upstream.
Which builds report this
162 of these reports name the Claude Code build they were running, spanning 90 releases. Heaviest reporters:
- Claude Code v2.0.76
- Claude Code v2.1.207
- Claude Code v2.1.206
- Claude Code v2.1.201
- Claude Code v2.1.247
- Claude Code v2.1.241
- Claude Code v2.1.234
- Claude Code v2.1.198
Report volume, not a defect count: an issue can mention a build without that build having caused the failure. Versions come from the version string in the bug-report template, matched against real published tags.
Do these get fixed?
Median time to close is 46 days across 503 closures. Of the 503 closures with a recorded reason, 10% were closed as completed and 451 as not-planned or duplicate. The most recent completed fix landed in 2026-08.
Workarounds reported by the community
52 of these issues post a workaround someone says worked. The highest-engagement ones:
- bypassPermissions mode not working in VS Code extension
- issue was reproduced on after upgrade IDE-VSCODE-CC-01-v1: Workaround — bypassPermissions in VSCode Extension Linked rule: [IDE-VSCODE-CC-01-v1](IDE-VSCODE-CC-01-v1.md) Upstream: [anthropics/claude-code 20536]( --- Envir…
Found in the thread of #20536 · still open - [BUG] Linux sandbox broken - bad bwrap calls and no allow permissions
- …ect root instead of protecting .git/HEAD, .git/config, etc. Workaround Added rooted patterns to .gitignore: /HEAD /config /hooks /objects /refs /.bash profile /.bashrc /.profile /.zprofile /.zshrc /.gitconfig /.gitmodule…
Found in the thread of #17727 · still open - [BUG] .claudeignore not ignoring private files
- …oses such as software testing or inter agent documentation. Workarounds to this scenario include changing while the agents are working and restoring it when doing git operations, or allowing agents to ignore which leads…
Found in the thread of #16704 · resolved - [BUG] ask list is ignored when "Bash" is in allow list
- …ands) and safety (protection against destructive commands). Workarounds attempted (none work) : - - Bypasses everything including ask list - - Prompts for every new command type
Found in the description of #6527 · still open - [FEATURE] GPU device passthrough in sandbox mode
- I did end up with a workaround, but this would be a really good feature to support natively so trickery is not required. 1. Ensure ~/.local/bin/ is on your PATH before /usr/bin 2. Make ~/.local/bin/bwrap: 3. Relaunch cla…
Found in the thread of #13108 · still open
Excerpts are quoted from the linked issue so you can judge relevance before opening it. Threads that only ask for a workaround, or report that there is none, are excluded. These are community suggestions, not official guidance from Anthropic — read the full thread before applying one.
Matching issues 1–100
Ranked by community engagement (reactions weighted over comments). Listing the top 300 of 752 matches; the statistics above cover all 752.
- [BUG] v2.1.150 adds server-side system prompt injection via `tengu_heron_brook` feature flag
- bypassPermissions mode not working in VS Code extension
- [BUG] Linux sandbox broken - bad bwrap calls and no allow permissions
- [BUG] .claudeignore not ignoring private files
- [BUG] ask list is ignored when "Bash" is in allow list
- [FEATURE] GPU device passthrough in sandbox mode
- [Feature Request] Add option to skip trust prompt when .claude/settings.local.json allows it
- [BUG] Claude accesses git origin server on startup before any commands issued
- Bash(command:*) allow rules do not prevent permission prompts for file-modifying commands
- [FEATURE] Linux (bwrap): Add allowUnixSockets / allowAllUnixSockets equivalent for seccomp BPF
- Sandbox (bubblewrap) fails in git worktrees due to .git file structure
- API Request Failure: Unexpected Usage Policy Violation Error
- Bug Report: Path Patterns in allowedTools Not Honored in Non-Interactive Mode
- [BUG] Claude refuses to write CLAUDE.md when it's a symlink
- [BUG] --dangerously-skip-permissions cannot be used with root/sudo privileges for security reasons
- [BUG] The Fetch tool of Claude Code does not identify properly but uses a generic UA
- [BUG] Permission request for 'xargs grep' even though settings allow 'xargs grep'
- [BUG] hasTrustDialogAccepted never persisted to ~/.claude.json despite repeated interactive sessions
- [BUG/UX] Sandbox network whitelist: No way to proactively configure domains, git operations fail without prompts
- [BUG][SECURITY] CLAUDE.md/AGENTS.md instruction compliance is architecturally unenforced — documented security consequences and 10+ independent reports
- [Feature Request] Add Session-Scoped Command Permissions
- Claude Code logs partial keystrokes and stores plaintext emails in ~/.claude.json
- ralph-wiggum plugin: Bash permission check fails despite allowed-tools declaration
- [BUG] Edit/Write tools bypass permissions.ask rules (regression of #11226)
- [BUG] ask permission rules don't take precedence over allow when Bash is in allow list
- [BUG] Claude continually asks for permission,even add permissin in .claude/settings.local.json
- [BUG] Two Claude Code sessions in the same folder / project share chat history when they should be separate.
- Deny Rules Configuration Failure in Claude Code CLI
- Shell snapshots base64-encode function bodies, making obfuscated content indistinguishable from a malicious payload
- [Bug] Claude refuses to fill in password fields in testing environment
- Use Linux system keychain (libsecret) for sensitive plugin credentials
- [BUG] Feature flag tengu_claudeai_mcp_connectors pushed server-side without consent
- [BUG] ## CRITICAL: Claude Code executed rm -rf deleting entire home directory
- [CRITICAL] Plugin-MCP Configuration Mismatch Causes Misleading 'Request Timed Out' Errors
- [BUG] Permissions Issue
- Is --allowedTools with --permission-mode bypassPermissions behavior expected?
- rm -rf command executed without permission despite explicit allow-list in settings.local.json
- [Feature Request] Support GPG commit signing in sandboxed environment
- [BUG] Sandbox fails with "bwrap: loopback: Failed RTM_NEWADDR: Operation not permitted"
- gh write commands execute without permission prompt despite Bash not being in allow list
- [BUG] TMPDIR not set in sandbox mode if bubblewrap is installed setuid root
- [BUG] Session Isolation Failure - Information Leaking Between Multiple Claude Code Sessions
- sandbox filesystem denyRead not enforced for Read tool or Bash commands
- [BUG] sandbox denyRead seems ineffective
- [BUG] dontAsk mode activates unexpectedly without user action
- [BUG] add_dirs Grants Filesystem Access to Read/Write Tools but Not to Bash Tool
- [BUG] DISABLE_TELEMETRY flag ignored - Claude Code connects to Google despite opt-out
- [Bug] Anthropic API Error: Unexpected Usage Policy Violation During Web Development Task
- [BUG] Commands working inconsistently
- [BUG] STOP INJECTING USER EMAILS INTO PROMPTS
- [BUG] skills and plugins share the same /plugin install surface
- [BUG] Devcontainer init-firewall.sh does not block IPv6 traffic
- [BUG] plugin-dev:command-development skill fails to load - false positive on bash security check 🐞
- Continuous undisclosed network calls to datadoghq.com every few seconds
- [BUG] Claude Code destroyed our codebase
- [BUG] `/sandbox` Sandbox mode is useless
- API Request Blocked: Potential Usage Policy Violation
- [P0 CRITICAL] Repeated false-positive “cybersecurity topic” blocks on legitimate commercial ops work involving Grokbot / xAI (Opus 4.7)
- [Bug] filesystem.denyRead not merged with Read(...) deny permissions in sandbox
- [Bug] Anthropic API Error: Overly broad safety filter blocks legitimate bioinformatics metadata requests
- [BUG] Could you, like, relax the "Usage Policy" violations a little? 🤣
- [BUG] Opening a new session without --resume does not clear session history (and /clear doesn't actually clear)
- [Bug][cyber] Debugging an H.264 video capture/extraction pipeline against known-good decoder output blocked (req_011CcY9KbFHf4xez9uNGQyAH)
- Forged `<system-reminder>` markup in subagent output is relayed unsanitized to the parent agent, impersonating a genuine system-reminder
- CLAUDE_CODE_EXPERIMENTAL_AGENT_TEAMS auto-distributor injects orchestrator/team task descriptions into specialist contexts as fake teammate messages
- GPG signing prompt conflicts with Claude Code TUI during git commit
- [BUG] mTLS client certificates broken in v2.1.23+ (works in v2.1.22)
- [BUG] Shell initialization (cd ~ in .bashrc) breaks workspace boundary
- [BUG] Security Bug Report: Claude Code Exposes Sensitive Environment Variables When Confused
- [Bug] Permission prompt misleading: claims "during this session" but grants permanent access
- [BUG] Content filtering policy blocking legitimate defensive security abuse report generation
- [Bug][cyber] Safety block halted authorized reverse-engineering of my own drone's auth protocol, mid-secret-re (req_011CcnReWU19UF1bg7REcCRy)
- [Bug][cyber] ClAudit false-positive in com — req_011CccPbdpfStasyx1ehijPs
- [Bug][cyber] Safety block interrupts legitimate security vulnerability analysis workflow (req_011CcY1o5TFLzNFaV7gPUFGo)
- [Bug][cyber] Blocked while reviewing a decompiled white-box AES class for app interop work (req_011CcV5MVf2AARSr2duriXsi)
- [Bug][cyber] Safety block interrupts legitimate open-source drone ground station development mid-session (req_011CcUWvRreLL6jx3hQHP7ob)
- [Bug][cyber] Safety block stops legitimate consumer drone firmware analysis via USB protocol inspection (req_011CcUBFqhJcvDBDuEgVegwF)
- [BUG] `sandbox.filesystem.denyRead` silently bypassed when target is inside a `denyWrite` directory
- [BUG] [Privacy Concern] Command suggestions showing URLs not in shell history from unknown source
- [Bug] Bash tool bypasses allowlist restrictions and executes unapproved commands
- [BUG] CLAUDE CODE running a git command without prompting resulting in catastrophic data loss
- [BUG] Dangerous rm -f command execution without permission
- [BUG] Claude Code cli tool not working with .claude/settings.json
- Inconsistent Permission Deny Rules for Symlinked/Mounted File Paths
- [BUG] CRITICAL BUG: Commands execute BEFORE user approval
- Background git access to the working repo's remote (SSH git-upload-pack) with no user-issued remote command, and no setting to disable it
- [Bug][cyber] Safety block halted routine memory-dump analysis of a mobile game process for reverse engineering (req_011CcnXGX2KkGqEv89H61eRm)
- [Bug][cyber] Safeguard blocked a routine "finish the task" continuation message with no security content (req_011CcnRnv4YvFFpaz45AjrWk)
- [Bug][cyber] False positive: safeguard blocked routine cloud IAM policy review and permission-scoping work (req_011Ccm9AiYP35wZYvf5jbWtw)
- [Bug][cyber] Safety block fired on routine request to audit repo for leaked secrets before making it public (req_011CckvjkmVEng3NE2wBmhGv)
- [Bug] Prompt injection attempt via user message appended payload
- [Bug][cyber] Building drone flight UI with live video + telemetry connection-status HUD blocked (req_011CcYJgUdojjgA9CLvAaxrz)
- [Bug][cyber] H.264 decoder debug blocked while inspecting CABAC corruption and unknown NAL types (req_011CcWya3V5wtjqdrbgxJhpd)
- [Bug][cyber] Safety block halted H.264 NAL-unit forensics: diagnosing CABAC corruption from suspicious NAL typ (req_011CcWyQ9hrc9xzACDwmp8mY)
- [Bug][cyber] Safety block interrupts APK unpacking/DEX decryption key analysis mid-session (req_011CcWUiMYd6DwbhzJSthUCh)
- [Bug][cyber] Cloud IAM audit/review work incorrectly flagged as unsafe cybersecurity content (req_011CcVvH7oDPuj7ZVtVbfnJy)
- [Bug][cyber] Safety block on consumer drone firmware downgrade feasibility question (req_011CcVtCm2xFhDbukwuYU5eB)
- [Bug][cyber] False block halts authorized defensive security automation app development (req_011CcV5RdTBsufs4i5UgJgz3)
- [Bug][cyber] Safety block halted reverse-engineering of a vendor SDK's white-box AES decrypt routine (req_011CcV5NTXoGuPu7Ju6gDkxg)
- [Bug][cyber] Safety block halted legitimate reverse-engineering of a white-box AES decryption routine (req_011CcV5M1QeTZMuGBQruYXZf)