One message, no permission prompt
Tel Aviv startup Accomplish has disclosed Beltdown, a sandbox escape in Anthropic’s Claude Code. An untrusted repository opened in the tool could run commands on a Mac as the logged-in user, outside the sandbox and with no permission prompt. Anthropic fixed it in Claude Code 2.1.247 on 26 August, according to the write-up by Accomplish principal security researcher Oren Yomtov, published on 11 September.
The researchers switched the sandbox on and chose the strictest “don’t ask” permission mode. They then opened a repository in Claude Code and sent one short message. A command from that repository ran on their Mac anyway.
How the escape worked
The route runs through core.fsmonitor, a git setting kept in a repository’s .git/config that names a shell command git runs when it looks at the working tree. Claude Code protects that file: its own file tools refuse to write inside a .git folder, and Seatbelt, the macOS sandbox, blocks bash from writing there.
Accomplish found the protection applied only to the .git folder at the project root. A setup script could build a git folder under a different name, write core.fsmonitor into its config and rename it to .git inside a subfolder, because the Seatbelt rule that would block renaming a nested .git folder was missing.

Claude is then asked to read a build report in that subfolder. According to Accomplish, that loads a skill, and loading a skill triggers a refresh of the file index through git ls-files. “The harness runs its own git commands outside the sandbox,” the researchers wrote, and that call had been left unhardened. Git read the nested config and ran the payload with the user’s full privileges. Accomplish said the chain can also be started through an indirect prompt injection.
A fix that took two attempts
Accomplish reported the flaw on 13 July and Anthropic triaged it the same day. A first round of hardening shipped in version 2.1.223 on 6 August, but it missed some git calls and the escape moved to another one, the researchers said. The full fix in 2.1.247 makes every git command the harness runs blank core.fsmonitor, so a repository’s config cannot run anything. The write-up covers macOS, cites no CVE and reports no exploitation in the wild.
How it differs from GitSpawn
The same setting was at the heart of GitSpawn, published by Manifold Security on 1 September and covered by Aivio News on 5 September. That research needed a repository delivered with a ready-made .git directory and fired through git commands agents run at startup; Manifold said Claude Code 2.1.196 patched its core.fsmonitor variant. Beltdown is a separate report, filed on 13 July, that builds the nested config from inside the sandbox and fires through a background indexing call.

A class of bug, not one product
On 12 September Accomplish published Beltdown2, which describes the same pattern in the Cursor CLI: its shell tool runs inside Seatbelt, but the harness’s own git ran outside it and honoured repository-supplied core.fsmonitor hooks. Anysphere fixed it in Cursor CLI 2026.08.04-aaa8809. “This is not a Cursor bug or a Claude bug. It is a class,” wrote Or Hiltch, Accomplish’s chief technology officer. The post lists OpenAI Codex among tools that harden every git call their harness makes.
Upstarts Media reported on 10 September that Accomplish also flagged two issues to OpenAI. An OpenAI spokesperson told the outlet both were addressed in August. Anthropic and Cursor did not respond on the record. Neither Beltdown post describes a Codex vulnerability.
What to watch
Beltdown is closed from Claude Code 2.1.247 onwards. A separate Claude Code path that Manifold reported on 15 July was still unpatched in version 2.1.252 when the firm retested on 1 September.