• Sources: primary, discussion
  • Summary: Accomplish AI describes Beltdown, an escape from the Claude Code sandbox on macOS that reaches command execution outside the sandbox. The writeup names two separate defects: the harness passes flags that blank core.fsmonitor on its out-of-sandbox git calls but missed git ls-files, and the Seatbelt profile lacks a rule that would block renaming a nested .git folder. Claude Code 2.1.247, released 2026-08-26, carries the fix, and earlier releases are affected.
  • Why it matters: Enabling the sandbox is what removes the permission prompt, so on Claude Code before 2.1.247 an untrusted repository could run commands outside the sandbox with nothing shown to the user.
  • Follow-up: Whether the same unhardened-subprocess pattern reaches other sandboxed agent CLIs, tracked alongside the earlier Docker-socket and Cowork VM escapes.

send feedback on this story