- Sources: primary, discussion
- Summary: Accomplish AI describes Beltdown, an escape from the Claude Code sandbox on macOS that reaches command execution outside the sandbox. The writeup names two separate defects: the harness passes flags that blank core.fsmonitor on its out-of-sandbox git calls but missed git ls-files, and the Seatbelt profile lacks a rule that would block renaming a nested .git folder. Claude Code 2.1.247, released 2026-08-26, carries the fix, and earlier releases are affected.
- Why it matters: Enabling the sandbox is what removes the permission prompt, so on Claude Code before 2.1.247 an untrusted repository could run commands outside the sandbox with nothing shown to the user.
- Follow-up: Whether the same unhardened-subprocess pattern reaches other sandboxed agent CLIs, tracked alongside the earlier Docker-socket and Cowork VM escapes.
send feedback on this story