Security issues on VS Code
Issues the maintainers labelled both platform:vscode and area:security.
82 issues · 27 open · 55 resolved (67%) · first seen Feb 23, 2026
Is this getting better or worse?
This class of problem is holding steady. 43 new reports in the last 90 days vs 35 in the 90 before — +23%. The open backlog peaked at 27 in 2026-08 and sits at 27 today.
Derived by counting each matching issue from its creation date until it closed. First-party
computation over the anthropics/claude-code tracker — the trend is not published
anywhere upstream.
Which builds report this
58 of these reports name the Claude Code build they were running, spanning 42 releases. Heaviest reporters:
- Claude Code v2.1.207
- Claude Code v2.1.185
- Claude Code v2.1.170
- Claude Code v2.1.72
- Claude Code v2.1.247
- Claude Code v2.1.227
- Claude Code v2.1.209
- Claude Code v2.1.206
Report volume, not a defect count: an issue can mention a build without that build having caused the failure. Versions come from the version string in the bug-report template, matched against real published tags.
Do these get fixed?
Median time to close is 34 days across 55 closures. Of the 55 closures with a recorded reason, 11% were closed as completed and 49 as not-planned or duplicate. The most recent completed fix landed in 2026-06.
Workarounds reported by the community
10 of these issues post a workaround someone says worked. The highest-engagement ones:
- [BUG] 2.1.193 VS Code extension (Windows, native): OAuth login fails "certificate has expired" — regression from 2.1.190
- …Encrypt chain), and adding the ESET root via does not help. Workarounds: (a) downgrade the extension to 2.1.190 ; or (b) remove/distrust the expired from the Windows certificate store (keeping ). Environment: Windows 10…
Found in the description of #71554 · resolved - [BUG] Workspace trust dialog never appears in the VS Code extension (shown via CLI), so project-scope plugins / project .claude/settings.json are silently skipped
- …ver load because trust can't be granted in-editor. The only workarounds are launching once via CLI per repo, or hand-editing in (undocumented; see 720). Related issues - 12227 (open) — same downstream consequence (untrus…
Found in the description of #67319 · still open - [FEATURE] Support VS Code-style ${input:id} secret prompts in .mcp.json for VS Code extension
- …Just click "OK" in the prompt Alternative Solutions Current workarounds tried: 1. System environment variables (current solution) — works but requires manual PowerShell setup per developer ( ) and a full VS Code restart…
Found in the description of #44158 · resolved - Read tool bypasses PreToolUse hooks and permissions.deny rules in VSCode extension
- What's Wrong? rules and PreToolUse/PostToolUse hooks are not enforced for the tool in the VSCode extension. Files that should be blocked by both layers are read successfully with f
Found in the description of #37540 · resolved - Security: IDE extension silently captures selected text, including secrets from .env files
- …ator when a selection is actively being captured as context Workaround Deselect all text before sending any message when working in or near credentials files.
Found in the description of #60062 · resolved
Excerpts are quoted from the linked issue so you can judge relevance before opening it. Threads that only ask for a workaround, or report that there is none, are excluded. These are community suggestions, not official guidance from Anthropic — read the full thread before applying one.
Matching issues 1–82
Ranked by community engagement (reactions weighted over comments).
- WebFetch summarizer emits <system-reminder> blocks in tool output, violating harness trust boundary
- [BUG] Claude 2.1.71 Security False Positives
- [BUG] 2.1.193 VS Code extension (Windows, native): OAuth login fails "certificate has expired" — regression from 2.1.190
- [BUG] IDE extension bypasses .claudeignore and settings.json deny rules (Auto-attach context leak)
- [BUG] Bash tool bypasses settings.json path deny rules — shell commands not subject to file tool access controls
- [BUG] Workspace trust dialog never appears in the VS Code extension (shown via CLI), so project-scope plugins / project .claude/settings.json are silently skipped
- [BUG] AUP repeatedly throwing false positives - live issue ongoing - hundreds of similar reports
- [FEATURE] Support VS Code-style ${input:id} secret prompts in .mcp.json for VS Code extension
- Claude Code drafts public bug reports containing sensitive project information without anonymising
- [BUG] Selection injection from `ide` MCP server has no documented suppression mechanism, leaks env file contents to conversation transport
- [BUG] IDE selection state persists across file close + new CLI session — closed file's selection re-appears in subsequent context
- [BUG] [privacy] Claude Max account email auto-injected into LLM context with no opt-out
- Bash tool executed `brew install` without prompting user for approval
- Read tool bypasses PreToolUse hooks and permissions.deny rules in VSCode extension
- Permissions bypassed and not persisted in VS Code/Cursor extension
- [Bug] Prompt injection attempt via user message appended payload
- [BUG] rm -rf with unexpanded ${LOCALAPPDATA} in bypassPermissions deletes real system directory
- Security: Claude Code exposed .env with private key via http.server, resulting in $1,324 theft
- [BUG] Claude Code ran destructive prisma db push against production database, causing complete data loss
- [Bug] Fable 5 cybersecurity classifier false positive on legitimate infrastructure administration tasks
- Security: IDE extension silently captures selected text, including secrets from .env files
- [BUG] Deny List not Honored for Edit/Write
- v2.1.121 VSCode native extension: permissions.deny rules not enforced
- [BUG] Claude Code builds CAPTCHA solver and tests against live system without user consent
- [Bug] Security: Command execution without user authorization
- [BUG] Security violation by design - leaking project details, memory on global scale
- [BUG] Bug report: assistant fabricated a user turn and system prompts inside its own response, then executed them
- Endless SecurityAgent prompt stack for "Claude Code-credentials": credential rewrite creates keychain partition mismatch, "Always Allow" can never persist (behavior persists after #41026 was closed as resolved)
- [Bug] Unauthorized autonomous merge with admin override bypassed branch protection
- [BUG] sandbox silently fails despite `failIfUnavailable` set to `true` in VSCode (Cursor) terminal
- Bash permission gate fires inconsistently in VS Code Claude extension — fails open on some commands not in allow list, fails closed on some commands that ARE in allow list
- [BUG] Calude Code (VSCode extension) not honoring .claudeignore file, and not catching that it should have, causing too much token consumption
- .claudeignore bypass: IDE selection sends ignored file contents as context
- [Bug] Claude Code reads environment variables ignoring the claudeignore
- Feature request: option to disable ide_opened_file context in VSCode extension
- Trusted Devices fails open on individual accounts: revoking devices doesn't re-verify an active session, and declining "Sign in again to verify your device" has no effect either
- Claude Code reads files matching a user CLAUDE.md 'never read' instruction
- MCP server 'supabase' sendo removido/adicionado repetidamente com comando malformado (openssl rand -hex 32 não interpolado)
- Prompt injection committed as a user message via --replay-user-messages (VS Code extension), not reproducible in bare CLI
- IDE selection from a closed, never-saved file leaks into model context (transmitted a secret)
- [BUG] Claude offers/accepts pasting secrets (API keys, tokens, passwords) directly into chat with no upfront warning
- [BUG] SECURITY RISK FORCING USERS FOLDER FOR .CLAUDE
- GitHub Copilot reading .claude/ configuration directory without explicit consent
- [BUG] CRITICAL: Bash permission gate bypassed for compound `rm -rf … && … | … ; echo …` commands in default mode (no allow-list match, no prompt shown, reproduced on 2.1.139)
- [Bug] Claude Code generates insecure deployments with exposed credentials and orphaned resources
- [BUG] Claude Code violated .gitignore/.claudeignore policy by reading .env file using Bash cat command in auto-approve mode
- Missing trust/permission prompt in VSCode/Positron extension vs CLI
- [BUG] managed-setting.json is bypassed when using Claude in VSCode combined with remote-ssh
- Add file exclusion for open-file context sent to Claude
- [BUG] There seems to be a hard coded "deny" on any dir/file containing the string "token"
- [BUG] API Error: Unable to connect to API: SSL certificate verification failed.
- Permission deny rules can be bypassed via Bash recursive grep and Glob filename listing
- [Bug] Missing safety validation for API requests
- [Bug] False positive security flag for HackTheBox program members
- Spoofed background-agent completion notification enabled a prompt injection attempt (correctly refused, full report filed on HackerOne)
- [BUG] Claude performed actions that were not approved
- [Bug] Security safeguards incorrectly flag defensive vulnerability analysis as offensive content
- [Bug] Security flags triggered during AI market tool build
- [Feature Request] Support for authorized web security testing workflows
- [BUG] Model committed with no user request, then quoted a confabulated commit-request message (absent from session JSONL)
- [Bug] Model fabricates user approval and executes destructive operations in plan mode
- [Bug] Security documentation missing from prompt guidelines
- [BUG] my /remote-control session got poisend with malicious prompt injections
- [Bug Report] Unable to generate issue title - no bug report content provided
- [Feature Request] Allow Claude Code to access and retrieve credentials
- [Bug] CTF Challenge Flagged as Suspicious - Legitimacy Verification Needed
- Compaction summary generates fabricated adversarial content, including instructions to conceal actions from the user
- Foreign third-party web-page content streamed into an in-flight assistant message (same requestId, +81s after reply ended)
- [Bug] Safeguard false positive flags legitimate AI-safety research workflow with valid cybersecurity authorization
- [BUG] Fabricated tool-call/tool-result blocks injected into conversation (VSCode extension)
- [MODEL] CRITICAL PERMISSION BYPASS: Claude manufactures its own execution authority from a document it wrote, overrides an explicit in-context user prohibition, and runs unapproved privileged commands
- [BUG] Agent unilaterally created/rotated a production API credential without asking
- Fabricated user message with non-standard <system_warning><ctx_interruption> wrapper appeared in model context after Esc interruption; absent from session transcript
- [Bug] Unexpected model change during active coding session
- [Bug] Excessive Safeguard False Positives During Defensive Security Audits
- [Feature Request] Support security-focused tasks in system prompts without safeguard restrictions
- [BUG] subagent (Task/Agent tool) results intermittently replaced with a fabricated "system-authority" prompt-injection ordering destructive git actions (`tool_uses: 0`)
- I appreciate you providing context, but I need to clarify my role: I'm designed to generate GitHub issue titles for Claude Code bug reports, not to evaluate security policies or make exceptions to security guidelines. If you believe there's a legitimate i
- [Feature Request] Model downgrade when safety guidelines flagged prevents access to higher reasoning tiers for safeguarding AI backed apps from prompt injection
- [Bug] Tool output injection attempting credential exfiltration to external endpoint
- Assistant output stream contaminated with stray synthetic data + fake system-reminder tag (persisted in assistant JSONL line); same-day phantom user message
- Claude Code v2.1.201 Bun binary SSL failure: UNABLE_TO_GET_ISSUER_CERT on macOS