Security issues on Windows
Issues the maintainers labelled both platform:windows and area:security.
255 issues · 70 open · 185 resolved (73%) · first seen May 20, 2025
Is this getting better or worse?
This class of problem is still growing. 98 new reports in the last 90 days vs 77 in the 90 before — +27%. The open backlog peaked at 70 in 2026-08 and sits at 70 today.
Derived by counting each matching issue from its creation date until it closed. First-party
computation over the anthropics/claude-code tracker — the trend is not published
anywhere upstream.
Which builds report this
123 of these reports name the Claude Code build they were running, spanning 77 releases. Heaviest reporters:
- Claude Code v2.1.237
- Claude Code v2.1.205
- Claude Code v2.0.76
- Claude Code v2.1.226
- Claude Code v2.1.245
- Claude Code v2.1.233
- Claude Code v2.1.229
- Claude Code v2.1.206
Report volume, not a defect count: an issue can mention a build without that build having caused the failure. Versions come from the version string in the bug-report template, matched against real published tags.
Do these get fixed?
Median time to close is 38 days across 185 closures. Of the 185 closures with a recorded reason, 21% were closed as completed and 146 as not-planned or duplicate. The most recent completed fix landed in 2026-08.
Workarounds reported by the community
55 of these issues post a workaround someone says worked. The highest-engagement ones:
- bypassPermissions mode not working in VS Code extension
- issue was reproduced on after upgrade IDE-VSCODE-CC-01-v1: Workaround — bypassPermissions in VSCode Extension Linked rule: [IDE-VSCODE-CC-01-v1](IDE-VSCODE-CC-01-v1.md) Upstream: [anthropics/claude-code 20536]( --- Envir…
Found in the thread of #20536 · still open - [BUG] Permission to read and edit files for session not being respected
- …It was working fine before the update this afternoon. Note As a workaround I'm launching claude with the --dangerously-skip-permissions option. This works, however, I'm closely watching the console to ensure it hasn't g…
Found in the description of #7104 · resolved - [BUG] Claude Code will not do anything without manual authorisation every single step
- Thanks for reporting this bug, we're working on a fix. In the meantime, if you need to work around this issue, you can temporarily downgrade to v1.0.102 where this functionality is working correctly.
Found in the thread of #7161 · resolved - Bug Report: Path Patterns in allowedTools Not Honored in Non-Interactive Mode
- …laude Code's security model in automated contexts. The only workaround is to use simple tool permissions without path patterns: bashclaude config add allowedTools Write No path pattern Or specify permissions directly via…
Found in the description of #1188 · resolved - [BUG] Sub agents can't use tools properly: `Permission to use xxx has been auto-denied in dontAsk mode` even with `--dangerously-skip-permissions`
- Related to 11881, fix allegedly incoming. In the meantime seems like rolling back to 2.0.42 helps some users.
Found in the thread of #11934 · resolved
Excerpts are quoted from the linked issue so you can judge relevance before opening it. Threads that only ask for a workaround, or report that there is none, are excluded. These are community suggestions, not official guidance from Anthropic — read the full thread before applying one.
Matching issues 1–100
Ranked by community engagement (reactions weighted over comments).
- bypassPermissions mode not working in VS Code extension
- [BUG] Claude on native Windows repeatedly asks to trust folder
- [BUG] Permission to read and edit files for session not being respected
- [BUG] Claude Code will not do anything without manual authorisation every single step
- [Feature Request] Native sandbox support for Windows (non-WSL)
- Bug Report: Path Patterns in allowedTools Not Honored in Non-Interactive Mode
- [BUG] Sub agents can't use tools properly: `Permission to use xxx has been auto-denied in dontAsk mode` even with `--dangerously-skip-permissions`
- [BUG] Cowork Windows - CSP blocks a-api.anthropic.com, VM starts but API unreachable (Win 11 25H2)
- Hard block on typing passwords breaks legitimate dev/test workflows - needs a permission-gated opt-in for own dev environments
- [BUG] Local MCP server will not trust self-signed certs
- Agent deleted 2,229 untracked source files without explicit user instruction — catastrophic unrecoverable data loss
- [BUG] OpenTelemetry telemetry cannot be disabled on Windows - outputs personal data every 30 seconds
- [BUG] ralph-wiggum stop hook triggered in separate session
- [BUG] .claudeignore does not prevent Claude from reading ignored files
- [BUG] NODE_EXTRA_CA_CERTS is not effective when set in ~/.claude/settings.json
- [BUG]
- Anthropic API Policy Violation Detection Incorrectly Blocking All User Inputs
- Claude Code exposes secrets from .env / .dev.vars files via grep -n and Read tool, despite CLAUDE.md prohibitions
- [BUG] Asking permission too often
- Authorized bounty/CTF security research blocked mid-session — need context-aware handling for whitehat workflows
- [BUG] Permission approval UI not displayed - operations immediately rejected without user interaction
- [BUG] DeprecationWarning: DEP0190 in Claude CLI due to shell: true usage
- [BUG] Claude code is NOT following strict instuctions inside of Claude.md
- [BUG] Claude Code `-EncodedCommand` PowerShell Execution Blocked by EDR/AV — No Opt-Out Available
- [FEATURE] Local password lock for Claude Code conversations (like Telegram)
- Phantom user turn carried a context-aware prompt-injection / data-exfiltration payload (Windows, CLI 2.1.160, Opus 4.8)
- PreToolUse hooks and --allowedTools not enforced in headless -p mode
- Documentation update for security. Claude overrides rules but this is not obvious and only reveals it after pain. Update documentation giving abstraction solution PLEASE
- [BUG] 2.1.193 VS Code extension (Windows, native): OAuth login fails "certificate has expired" — regression from 2.1.190
- [BUG] IDE extension bypasses .claudeignore and settings.json deny rules (Auto-attach context leak)
- Own code, market as Malware and refuses to make edits, after an hour I still worked what is happening?
- [BUG] Bash tool bypasses settings.json path deny rules — shell commands not subject to file tool access controls
- [BUG] LOST DB INFORMATION DUE TO CLAUDE NOT ASKING PERMISSIONS
- Desktop Browser pane: allow user-approved local hostnames (hosts-file aliases) as trusted preview origins — currently all subresources blocked with ERR_BLOCKED_BY_CLIENT
- Claude Desktop Code tab ignores NODE_EXTRA_CA_CERTS on Windows MSIX install behind corporate SSL proxy
- Security: permission enforcement relies on LLM judgment rather than hard rules, settings.local.json may be bypassed
- [BUG] # Claude Code v1.0.103 Critical Bug Report
- [Bug] Security Vulnerability: Permissions Bypass via ExitPlanMode Workflow Exploit
- [BUG] AUP repeatedly throwing false positives - live issue ongoing - hundreds of similar reports
- system-reminder nudges ("NEVER mention this reminder to the user") are indistinguishable from prompt-injection attacks and cause false positives
- [Bug] Update 1.1.7714 broke Claude Code desktop app — ccd-cli passes --allow-dangerously-skip-permissions as root + Hyper-V not initializing on Windows
- [BUG] Windows: Drive Letter Change Triggers Permission Resolver Explosion + Arbitrary .claude/ Directory Creation Outside Workspace
- [BUG] I was asking Claude Code to review my privacy settings, and this was one of the searches it did. I believe this user is one of the Claude Code devs.
- [BUG] Phantom user messages - commands executed without user input
- Permission System Bypass: Unauthorized .env File Access
- [BUG] security-guidance plugin: `_glob_match` docstring says `**` matches any depth, but fnmatch implementation silently excludes top-level files from security rules
- [BUG] Unacceptable File Access
- [BUG] Claude Code permission bypass using @../ attachment syntax outside workspace boundary
- [BUG] Desktop: misbehaving DXT can spam unblockable file-attach consent dialog with no UI escape
- enableAllProjectMcpServers should default to false for security
- Require user consent before auto downloading update installers
- [BUG] SELF_SIGNED_CERT_IN_CHAIN Error: Extension Fails in Corporate Proxy Environment (Zscaler)
- [BUG] AI agent violates explicit "NO COMMITS without approval" rule in CLAUDE.md
- [BUG] Spoofed/fabricated tool results injected into the session[Opus 4.8]
- [BUG] No permission prompt before reading/searching files OUTSIDE the working directory
- [BUG] Subagent autonomously ran destructive DELETE scripts against production data
- [BUG] IDE selection state persists across file close + new CLI session — closed file's selection re-appears in subsequent context
- Path-pattern scanner false-positives on Windows 8.3 short names (e.g. ALICEM~1), bypassing user allow-rules — affects users with non-ASCII chars in their Windows username
- [BUG] claude should not be allowed to start claude. (Denial of service vulnerability: exploit with prompt: "sessions")
- [Bug] Unsafe directory traversal attempt during /init - attempted parent directory access
- [BUG] Explore subagent should request permission before fetching web content (prompt injection risk)
- [BUG] `disallowedTools: [Write, Edit]` trivially bypassed via Bash tool — agents use sed/awk/redirects to modify files
- [BUG] Cross-session credential leak in conversation summary (context continuation)
- Bug: Claude executes destructive git checkout without confirmation
- security-guidance plugin fails on Windows - uses python3 instead of python
- [BUG] Claude's PowerShell workaround for Edit tool failures caused file corruption and data loss
- [BUG] Claude deleting files without requesting permission
- Security hook blocks legitimate mentions in documentation files
- [Feature Request] Prevent Unintended Database Destruction via Confirmation Prompt
- [BUG] EDITED: Claude Code fails on mobile networks due to IP-based connections instead of hostname-based HTTPS
- dangerouslyDisableSandbox allows the model to bypass workspace boundaries without a distinct, explicit user confirmation
- Plugin safety: third-party plugins can silently disable auto_memory via env vars
- [FEATURE] Allowlist-only file access + deny rules for MCP tools (WebFetch, WebSearch)
- Granular control over <system-reminder> injections (env var / settings)
- Unexpected message injection — text from WhatsApp appeared in Claude Code session
- [BUG] Managed hooks restriction bypassed when using ANTHROPIC_BASE_URL
- [BUG] Cowork: Agent autonomously explores filesystem outside sandbox boundary (Windows 11)
- [BUG] `--allowedTools` has no effect when permission bypass flags are active
- [BUG] Claude Code executed rm -rf /* on production VPS due to SSH variable escaping error
- [DOCS] PowerShell tool docs omit dangerous-command safety behavior
- [BUG] rm -rf with unexpanded ${LOCALAPPDATA} in bypassPermissions deletes real system directory
- [BUG] .claudeignore deny list bypassed by Agent tool sub-process — blocked *.json files were read and modified
- [BUG] Claude Code ran destructive prisma db push against production database, causing complete data loss
- Claude Code accessing files outside workspace directory (triggering Dropbox downloads)
- [BUG] Project-level allow rules cannot override user-level deny rules for path patterns
- [Bug] Critical Security Vulnerability in Claude Code
- [BUG] Claude Code randomly nukes claude.json in wsl
- Native Windows: working directory does not scope shell-tool filesystem access
- [BUG] /feedback sends Git repository + SSH commands with customer personal data
- [BUG] Deny rules in settings.json are not enforced — denied files and commands remain accessible`
- `claude mcp remove` expands `${VAR}` env-var references inline in `.mcp.json`, leaking secrets
- Claude misidentifies legitimate system reminder as prompt-injection attack hosted on fetched URL
- # Malformed flag `-dangerously-skip-permissions` (single dash) silently enables `--debug` via prefix match
- [BUG] Malformed settings.json files are silently skipped if they become incorrect after session startup.
- [BUG] Claude Code builds CAPTCHA solver and tests against live system without user consent
- [BUG] Explore agent triggers unscoped file access, causing OneDrive to download cloud-only files
- [BUG] Security violation by design - leaking project details, memory on global scale
- [BUG] Data loss caused by Claude Code — unauthorized destructive command
- [BUG]
- Feature Request: Native GUI Password Prompt for Sudo Commands