anthropics / anthropics/claude-code

[Bug] Unauthorized file system access beyond explicitly permitted directories

Open
#95,170 0 comments 0 reactions 0 assignees View on GitHub
area:desktop area:permissions area:sandbox bug platform:windows
Dominant language
Python
Stars
145k
Forks
23.1k
PR merge metrics
PR metrics pending

Description

**Bug Description**
On 2026-09-16, in a Cluade Code desktop sesssion on my PlaidLoom project, Claude ran a search of my Downloads, Desktop, and Documents folders. It was looking for ZIP files matching names it had seen in my production database. I had not given it access to any of those folders. In fact, I have told Claude before that it may only access folders I explicitly name. If found the files it was looking for and read the 19 zipfiles and extracted parts of one into its temporary folder. I want to know why the tool ignore clear rules and directives and violated my privacy and searched my computer files. I want to know why the tool let this happen without asking me , how to prevent it, and ask for compensationin the form of future credit toward my monthly bill.

**Environment Info**
- Platform: win32
- Terminal: claude-desktop
- Version: 2.1.220
- Feedback ID: f4c8f66d-c0c3-4154-950c-85a46e82dcab

**Errors**
```json
[]
```

Contributor guide

No contributing guide indexed for this repository

Research direction

No files, tests, or code entry points are mentioned. Start with the supplied Feedback ID and the win32 Claude Desktop 2.1.220 session details; done means confirming the access path and documenting how permission or consent behavior should prevent it.

Written by the indexing model from the issue text.

Assessment

Domain
operating-systems, security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.