The sandbox issues on Windows
Issues the maintainers labelled both platform:windows and area:sandbox.
72 issues · 27 open · 45 resolved (63%) · first seen Feb 26, 2026
Is this getting better or worse?
This class of problem is holding steady. 39 new reports in the last 90 days vs 32 in the 90 before — +22%. The open backlog peaked at 27 in 2026-08 and sits at 27 today.
Derived by counting each matching issue from its creation date until it closed. First-party
computation over the anthropics/claude-code tracker — the trend is not published
anywhere upstream.
Which builds report this
29 of these reports name the Claude Code build they were running, spanning 26 releases. Heaviest reporters:
- Claude Code v2.1.197
- Claude Code v2.1.98
- Claude Code v2.1.92
- Claude Code v2.1.220
- Claude Code v2.1.241
- Claude Code v2.1.178
- Claude Code v2.1.207
- Claude Code v2.1.233
Report volume, not a defect count: an issue can mention a build without that build having caused the failure. Versions come from the version string in the bug-report template, matched against real published tags.
Do these get fixed?
Median time to close is 37 days across 45 closures. Of the 45 closures with a recorded reason, 16% were closed as completed and 38 as not-planned or duplicate. The most recent completed fix landed in 2026-08.
Workarounds reported by the community
27 of these issues post a workaround someone says worked. The highest-engagement ones:
- [BUG] Cowork on Windows: bash sandbox can create files on mounted host folder but unlink is denied — breaks all git write operations
- …eyboards were destroyed in the repeated attempts to explore workarounds. When using Claude Code (Desktop and CLI) I did not hit this issue. Bummer, as I'm enjoying Cowork Desktop and am excited to see this resolved. I ha…
Found in the thread of #55206 · still open - [BUG] RPC error: useradd failed (exit status 12) — cannot start any new Cowork tasks
- FYI following the workaround: Workaround Fully quit Claude Desktop mv "~/Library/Application Support/Claude/vm bundles/claudevm.bundle/sessiondata.img" ~/Desktop/sessiondata.img.bak Restart Claude Desktop (recreates the…
Found in the thread of #36465 · resolved - Read tool PDF support broken on Windows — sandbox rejects pdftoppm from all locations
- …rShell within the same Claude Code session works perfectly: Workaround Two-step process via Bash: 1. Convert PDF to PNG: 2. Read the PNG with the Read tool This works reliably but requires extra Bash permission prompts a…
Found in the description of #65089 · still open - [Bug] Claude Desktop VM workspace startup failure: path mismatch between AppData\Roaming and AppData\Local
- …ical - bash/workspace entirely unavailable Status Resolved (workaround applied) --- Summary After a Claude Desktop update, the Cowork bash/workspace sandbox failed to start on every session. The Linux VM could not be ini…
Found in the description of #56542 · resolved - [BUG] Cowork stale-cache corruption reproduced under Claude Fable 5 — host writes are clean on disk, the sandbox read view truncates (full diagnosis + fix)
- …System Windows Terminal/Shell Other Additional Information Workarounds in production use across seven document projects (validated over three weeks): - Treat host-tool writes and sandbox reads as separate worlds. After…
Found in the description of #67585 · still open
Excerpts are quoted from the linked issue so you can judge relevance before opening it. Threads that only ask for a workaround, or report that there is none, are excluded. These are community suggestions, not official guidance from Anthropic — read the full thread before applying one.
Matching issues 1–72
Ranked by community engagement (reactions weighted over comments).
- [Feature Request] Native sandbox support for Windows (non-WSL)
- [BUG] Cowork on Windows: bash sandbox can create files on mounted host folder but unlink is denied — breaks all git write operations
- [BUG] RPC error: useradd failed (exit status 12) — cannot start any new Cowork tasks
- Read tool PDF support broken on Windows — sandbox rejects pdftoppm from all locations
- [Bug] Claude Desktop VM workspace startup failure: path mismatch between AppData\Roaming and AppData\Local
- [Bug] Linux sandbox unavailable: bash hard failure preventing tool execution
- [BUG] Cowork stale-cache corruption reproduced under Claude Fable 5 — host writes are clean on disk, the sandbox read view truncates (full diagnosis + fix)
- [Bug] virtiofs mount serves truncated file contents to sandboxed environment while host files are clean
- [BUG] Cowork sandbox VM bundle not found in Roaming path on Windows 10 Pro (Store/AppX install) — hardlink workaround
- Worktree sessions can edit files in the parent main checkout with no guardrail
- [BUG] Cowork sandbox fails at sdk_install on Windows — VM guest crashes with "connection forcibly closed" (regression SDK 2.1.181 → 2.1.202)
- [BUG] Cowork scheduled task reads stale filesystem snapshot between invocations (Windows)
- [BUG] Windows: ENOENT mkdir 'E:\claude-tmp\...\tasks' — all Bash tool calls fail
- [BUG] Virtualization is not available Claude's workspace requires Virtual Machine Platform, but the virtualization service isn't responding. Restart your computer to resolve this.
- dangerouslyDisableSandbox allows the model to bypass workspace boundaries without a distinct, explicit user confirmation
- [BUG] Claude-spawned child shells on Windows can't complete new outbound TLS handshakes to non-Anthropic endpoints (breaks Perforce)
- Auto mode still triggers permission prompts for PowerShell registry writes on Windows
- [BUG] Cowork: Agent autonomously explores filesystem outside sandbox boundary (Windows 11)
- [BUG] rm -rf with unexpanded ${LOCALAPPDATA} in bypassPermissions deletes real system directory
- Native Windows: working directory does not scope shell-tool filesystem access
- [BUG] Hanging find.exe
- PowerShell tool: non-overridable "Remove-Item on system path" guard over-blocks legitimate commands (AST target mis-attribution)
- [BUG] Cowork: virtiofs mount cache not invalidated on Windows host file saves — BadZipFile on Excel save (ref #42520)
- [Cowork] Sandbox disk stuck at 100% full, not cleared by app or PC restart
- [MODEL] opus
- [BUG] Cowork fails with Plan9 share 'd': HRESULT 0x80070005 - Windows (Microsoft Store install)
- [SOLUTION] RPC error -1: virtiofs mount Plan9 mount failed: bad address — Working Recovery Script + Fix Pattern (Windows 11 Pro)
- [BUG] Cowork sandbox VM leaks on Windows - orphaned vmmem/vmwp (cowork-vm-*) keeps running after app quit
- [BUG] Cowork sandbox bash tool caps timeout_ms at 45000, no way to run longer commands
- [BUG] Cowork: mount serves null bytes for rename target after recreating rename-source path — git unusable on mounted folders
- [FEATURE] I would like to be able to run the claude windows app as a different user
- [BUG] Claude wrote files to system temp folder (AppData\Local\Temp) without disclosure
- [Bug] Sub-agent `rm -rf` with case-insensitive path collision destroys workspace; no sandbox, confirmation, or orchestrator interception
- Sandbox blocks tmux (psmux) when cwd is home directory on Windows
- [BUG] sandbox.filesystem.allowWrite not enforced when using --dangerously-skip-permissions
- [BUG] Windows: sandbox bash ignores CLAUDE_CODE_SHELL and sandbox.enabled: false (v2.1.59)
- [BUG] Browser pane blocks all subresources from a PUBLIC internet domain with ERR_BLOCKED_BY_CLIENT (same symptom as #87472, but not an RFC1918 address)
- Claude Code bypassed a blocked system-path guard via 'cmd /c rd', then a destructive command silently continued unsupervised in the background after timeout — wiped C:\ drive root
- [BUG] Windows sandbox breaks Gradle/JVM loopback IPC ("Unable to establish loopback connection") — still repros on 2.1.209 (#44857 closed without fix)
- [BUG] Windows 11: Write tool and Bash tool cannot write files visible to the real file system
- Support Microsoft MXC sandboxing
- [BUG] `codex_sandbox` firewall rules cause intermittent ECONNRESET in VS Code extension (Windows)
- [BUG] Claude-spawned child shells on Windows can't complete new outbound TLS handshakes to non-Anthropic endpoints (breaks Perforce)
- [BUG] Bash tool bypasses configured working directory boundaries
- Sandbox denies user-approved Management API PATCH even after explicit AskUserQuestion authorization
- [BUG] CoWork: Edit tool silently hangs on /mnt/.claude/ (read-only mount) — no error, turn produces no output
- [BUG] Cowork Windows: bwrap sandbox torn down between turns, killing background processes (works on Mac)
- [BUG] Process gets killed with SIGTERM ~90 seconds later ❌
- Agent tool: isolation:"worktree" subagent read parent session's private transcript outside its worktree
- Native Windows: working directory does not scope shell-tool filesystem access
- (Bug) Terminal tool spawns Gradle/Java processes that fail loopback handshake — Unable to establish loopback connection
- [BUG] PowerShell guard blocks Remove-Item for any direct child of a drive root, including nonexistent paths
- Windows desktop app: projects, memory, and sandboxing are invisible or missing - field report from shipping a real product through it
- Bash tool blocked (even read-only) when safety-classifier model is unavailable; dangerouslyDisableSandbox does not override
- [BUG]
- [BUG] Claude Code create c:/memfs directory without asking me.
- [BUG] Files over some size threshold (in my skill's case, a file >614 lines / >23,458 bytes) get cut off in the Linux-sandbox view, preventing skill from executing on Windows
- PowerShell tool: pwsh.exe fails with "Permission denied" (exit 126) inside sandboxed session, while powershell.exe works fine
- PowerShell safety guard: Spanish word "del" inside a quoted commit message is treated as Remove-Item, then blocks on a quote-split path fragment
- please delete this issue. thank you
- [BUG] Linux sandbox stuck on "Workspace still starting" forever on Windows 11 (Cowork/Code)
- Worktree command-safety analyzer misreads a non-leading `complete`/`compgen`/`compopt` token as an invoked builtin
- auto-mode classifier did not block an agent-authored script that ran `git clean -xdff` at the workspace root (21 projects destroyed, native Windows)
- Sub-agent ran recursive delete outside working dir, wiped entire user profile (~235k files); safety classifier failed open
- [BUG] Managed.settings.json & settings.json
- [FEATURE] Workspace boundary enforcement for local file writes — auto mode allows out-of-workspace Bash writes silently; recommended alternative (sandbox) unavailable on native Windows
- [BUG] Cowork sandbox mount serves recently-grown files truncated to a stale cached size
- [Cowork] mcp__workspace__bash sandbox VM fails to start — persistent multi-session outage
- Cowork session storage resolves through redirected AppData\Roaming (UNC path) even after reinstall, breaking sandbox operations entirely
- Sandbox mode blocks named pipe creation on native Windows (EACCES), contradicting docs that say sandboxing is WSL2-only
- [BUG] Sandbox bash mount returns truncated/partial file reads (Cowork mode)
- Windows: Write/Edit tools fail with spurious EEXIST on sandboxed workspace (bindflt/bfs mount) — temp file does not exist