Claude Code’s network sandbox cannot be treated as a hard containment boundary if the outbound filter and the runtime disagree on where a request goes. A hostname allowlist can approve traffic the OS later resolves differently, which means patching closes the bug but does not change the fact that a prompt-injection chain could turn the agent into an exfiltration path.
Anthropic fixed the issue in Claude Code 2.1.90 after the bypass was found, and the product had already shipped 2.1.88 before the report was filed. The flaw is tracked as CVE-2025-66479 and is described as a SOCKS5 hostname null-byte injection that affected the network sandbox from its general availability on October 20, 2025 until version 2.1.90.
For teams using Claude Code in security-sensitive workflows, the key risk is that sandbox controls can fail at the boundary between policy enforcement and network resolution. That leaves outbound approval logic weaker than operators may assume when attacker-controlled prompts or tools can influence requests.