Security issues on Windows — page 2
Issues the maintainers labelled both platform:windows and area:security.
255 issues · 70 open · 185 resolved (73%) · first seen May 20, 2025
Is this getting better or worse?
This class of problem is still growing. 98 new reports in the last 90 days vs 77 in the 90 before — +27%. The open backlog peaked at 70 in 2026-08 and sits at 70 today.
Derived by counting each matching issue from its creation date until it closed. First-party
computation over the anthropics/claude-code tracker — the trend is not published
anywhere upstream.
Which builds report this
123 of these reports name the Claude Code build they were running, spanning 77 releases. Heaviest reporters:
- Claude Code v2.1.237
- Claude Code v2.1.205
- Claude Code v2.0.76
- Claude Code v2.1.226
- Claude Code v2.1.245
- Claude Code v2.1.233
- Claude Code v2.1.229
- Claude Code v2.1.206
Report volume, not a defect count: an issue can mention a build without that build having caused the failure. Versions come from the version string in the bug-report template, matched against real published tags.
Do these get fixed?
Median time to close is 38 days across 185 closures. Of the 185 closures with a recorded reason, 21% were closed as completed and 146 as not-planned or duplicate. The most recent completed fix landed in 2026-08.
Workarounds reported by the community
55 of these issues post a workaround someone says worked. The highest-engagement ones:
- bypassPermissions mode not working in VS Code extension
- issue was reproduced on after upgrade IDE-VSCODE-CC-01-v1: Workaround — bypassPermissions in VSCode Extension Linked rule: [IDE-VSCODE-CC-01-v1](IDE-VSCODE-CC-01-v1.md) Upstream: [anthropics/claude-code 20536]( --- Envir…
Found in the thread of #20536 · still open - [BUG] Permission to read and edit files for session not being respected
- …It was working fine before the update this afternoon. Note As a workaround I'm launching claude with the --dangerously-skip-permissions option. This works, however, I'm closely watching the console to ensure it hasn't g…
Found in the description of #7104 · resolved - [BUG] Claude Code will not do anything without manual authorisation every single step
- Thanks for reporting this bug, we're working on a fix. In the meantime, if you need to work around this issue, you can temporarily downgrade to v1.0.102 where this functionality is working correctly.
Found in the thread of #7161 · resolved - Bug Report: Path Patterns in allowedTools Not Honored in Non-Interactive Mode
- …laude Code's security model in automated contexts. The only workaround is to use simple tool permissions without path patterns: bashclaude config add allowedTools Write No path pattern Or specify permissions directly via…
Found in the description of #1188 · resolved - [BUG] Sub agents can't use tools properly: `Permission to use xxx has been auto-denied in dontAsk mode` even with `--dangerously-skip-permissions`
- Related to 11881, fix allegedly incoming. In the meantime seems like rolling back to 2.0.42 helps some users.
Found in the thread of #11934 · resolved
Excerpts are quoted from the linked issue so you can judge relevance before opening it. Threads that only ask for a workaround, or report that there is none, are excluded. These are community suggestions, not official guidance from Anthropic — read the full thread before applying one.
Matching issues 101–200
Ranked by community engagement (reactions weighted over comments).
- [BUG] MCP OAuth: state parameter not sent in authorize request but validated on callback
- Opus Model : Antivirus detected as misbehavior
- [BUG] Workspace Trust Dialog Not Respecting Pre-configured ~/.claude/.claude.json
- [Bug] Dangerous rm Command Execution with Unintended Path Parsing
- Permissions Validation Override Not Working in Plan Mode
- Filesystem MCP access limited to WSL directories - need full computer access
- Windows Permission Persistence Failure During CLI Startup
- [Bug] False positive safety flag on cybersecurity website design tasks
- [Bug] Security vulnerability: Private repository data exposed to production without filtering
- [FEATURE] Claude in Chrome: connected browser can be driven cross-machine with no reliable device identification
- Subagent replies delivered to the wrong session when multiple sessions run agents concurrently (Windows)
- [BUG] Remote Control SSE channel (worker/events/stream) ignores NODE_EXTRA_CA_CERTS while the API channel honors it — same process, v2.1.201 (it's Node, not Bun)
- [BUG] OAuth login/refresh fails with UNABLE_TO_GET_ISSUER_CERT on platform.claude.com's new Let's Encrypt (ISRG Root X2 cross-signed) chain
- [BUG][SECURITY] Tool results appear to be modified after execution with injected pseudo-"system instructions" repeatedly urging destructive `git push --force` (Cowork research preview, Windows)
- [BUG] Scheduled task creation fails on Windows with UNC-redirected Documents folder
- Hook path with spaces in username executes wrong file on Windows — unquoted ~ expansion splits path at space
- [BUG] Safety classifier false positives block benign questions in security-context sessions
- Enhancement - auto appends
- UserPromptSubmit hook: decision: "block" does not erase typed prompt from model context
- [BUG] SECURITY: claude-in-chrome MCP controls browsers across different Claude accounts (extends #33813)
- Conversation history leak via FileChanged notifications bypasses guard hooks and gitignore
- [BUG]
- [BUG] Calude Code (VSCode extension) not honoring .claudeignore file, and not catching that it should have, causing too much token consumption
- [BUG] Claude Code (Windows) fails under enterprise SSL inspection — ignores system & custom CA trust
- Default to private when creating GitHub repositories
- Playwright MCP silently hijacks all Chrome downloads to temp folder
- remote-control rejects workspace trust set in .claude.json on Windows
- [BUG] Suspicious tip/hint displayed during active tool use suggesting fake plugin install command
- [BUG] PreToolUse hooks exit code ignored - operations proceed after hook failure
- C:/Program Files/Git/clear command does not clear terminal scrollback - previous session data remains visible
- [BUG] <system-reminder> can read sensitive selected text from .env files, no hooks available to protect our files
- [DOCS] Missing configuration example for Windows WebDAV security warning
- Claude Code executed forbidden rollback command and repeatedly violated explicit safety instructions despite CLAUDE.md prohibitions
- Windows: libsafewoo DLL deleted by Chinese antivirus software (360, Huorong)
- security-guidance plugin fails on Windows: python3 command not found
- [BUG] IP from someone else and not from my conversation
- [BUG] Approval patterns with environment variables don't match
- Issue Report: Claude Code Used Unknown IP Address
- [BUG] security-guidance plugin hook fails on Windows paths with spaces Body
- [Bug] Code execution occurring mid-response before user confirmation
- [BUG] Windows Claude Code versions after 2.0.24 signed with expired certificate
- [BUG] MCP Permission Bypass Regression - Post-Outage Issue Affecting Multiple Accounts
- "MongoDB Maintenance Operations Blocked - Critical Policy Issue"
- [Bug] HTML Artifact Causes Desktop Application Renderer Instability
- [Bug] Unauthorized Code Commit Without User Approval
- [Bug] Anthropic API Error: Unexpected False Positive AUP Violation
- [BUG]
- [BUG] Unauthorizied Directory Traversal
- [BUG] Permission deny patterns not working for Read/Write tools in settings.local.json
- Trusted Devices fails open on individual accounts: revoking devices doesn't re-verify an active session, and declining "Sign in again to verify your device" has no effect either
- [BUG] Desktop GUI session delete removes only the registry entry — plaintext transcript remains on disk (indefinitely if `cleanupPeriodDays` is raised)
- [edit] I'm dumb and was melodramatic.
- `.claude.json` stores one project directory under up to three different path spellings, splitting trust, MCP servers, and worktree state across them
- Suspected prompt injection in background subagent tool-result stream (Bash), instructing agent to conceal file state from user
- Claude Code bypassed a blocked system-path guard via 'cmd /c rd', then a destructive command silently continued unsupervised in the background after timeout — wiped C:\ drive root
- claude mcp add --header exposes Authorization/Bearer token value in stdout
- PowerShell safety guard false positive: here-string body text with paths like /requirements.txt blocked as 'Remove-Item on system path'
- Support Microsoft MXC sandboxing
- [BUG] SECURITY RISK FORCING USERS FOLDER FOR .CLAUDE
- [BUG] Repo-level .claude/settings.json not loaded when session is rooted at a parent directory
- `claude mcp add` echoes Authorization header value verbatim to stdout, leaks bearer tokens to terminal and session transcripts
- security-guidance: Stop-hook LLM review broken on Windows when worktree has many untracked files (WinError 206)
- [Critical] /init command causes Explore agent to read files from unrelated project directories
- Claude circumvents Bash permission restrictions by switching to PowerShell
- Secret leak: agents read .env / credential files without redaction; remediation pushed onto user
- Model recommended inline-secret command that leaks rescue admin password in Claude-isolation setup
- [Windows/Git Bash] PreToolUse hook enforcement silently bypassed — hooks exit 49 with no output or warning when python3 resolves to Store stub
- [Bug] Claude Code generates insecure deployments with exposed credentials and orphaned resources
- [BUG] WebFetch permission bypassed
- [BUG] Windows clipboard write exposes content in PowerShell argv (captured by EDR/SIEM ProcessCommandLine telemetry)
- Claude Code repeatedly violates user-defined CLAUDE.md rules within same session (credential handling)
- [Feature request] Local Claude Code logs allow state reset via manual deletion
- [BUG] `claude mcp get` and `claude mcp add --header` print Authorization header values unredacted to stdout
- Cross-device MCP browser command routing — UX concern + feature feedback
- [BUG] Access Token visible in Marketplace menu
- Cowork silently executes browser automation on unattended remote machine via shared account
- Missing trust/permission prompt in VSCode/Positron extension vs CLI
- Claude Code umgeht PreToolUse:Edit Hook durch Python-Script via Bash
- [BUG] Content filter falsely blocks transcription of 1986 agricultural newsletter
- CRITICAL: robocopy /MIR deletes local files due to UNC path misinterpretation
- [FEATURE] Block WebDAV paths by default on Windows to prevent permission bypass
- [BUG] Security: Cross-account session data exposure between Personal Pro and Teams accounts
- Security reminder should detect workflow files on Windows paths
- [BUG] statusline-setup agent uses wrong username (data leakage between users)
- [BUG] File permission deny rules not enforced on Windows native version with Git Bash (works correctly on WSL)
- Where is the enterprise managed policy settings files in windows system for claude code 1.0.51 version
- [BUG] Simple prompt copy paste triggers [cyber] safeguard
- [BUG] Per-device session visibility — sidebar leaks session titles across machines on one account
- [BUG] Claude in Chrome side panel shows "refused to connect" — claude.ai/a.claude.ai frames blocked by CSP frame-ancestors missing the extension origin
- [Bug] Log4Shell probe string in file content triggers connection reset instead of safeguard message
- [Bug] Context leakage between unrelated projects across sessions
- Agent tool: isolation:"worktree" subagent read parent session's private transcript outside its worktree
- Native Windows: working directory does not scope shell-tool filesystem access
- [MODEL] Opus 4.8 fabricated user messages 6+ times in one long session and "answered" them; cyber safeguard then blocked the user's request to audit the transcript
- [BUG] No path-level exclusion for sensitive files in file-change-notification behavior
- [Bug] Security scan incorrectly flags user's own source code as suspicious
- Security: undeclared HTTP MCP transport persisted with credentials in global .credentials.json, presented as a project MCP, survives config removal
- [BUG] Claude CLI Subscription Type Modification / Plan Escalation Issue
- [BUG] my /remote-control session got poisend with malicious prompt injections
- [Feature Request] Blue team exercise context to suppress false positive alerts