Claude Debugs and Fixes Its Own MCP Filesystem Server UNC Path Bug on Windows

A developer documented using Claude Opus to debug and fix a bug in the MCP Filesystem Server (Desktop Extension version) on Windows. The issue affected UNC network share paths (e.g., \\server\share\).
The Problem
When using a UNC share as an allowed directory, list_directory on the share root worked, but any operation on subdirectories or files failed with an "Access denied - path outside allowed directories" error. Writing files to the root also failed, despite the share being fully accessible from Windows Explorer and mapped drives.
The Debugging Process
Claude helped identify that:
- The configuration for the Desktop Extension version is stored in
%APPDATA%\Claude\Claude Extensions Settings\ant.dir.ant.anthropic.filesystem.json, notclaude_desktop_config.json. - Switching to a mapped drive letter didn't work because Node.js
fs.realpath()resolves mapped drives back to UNC paths during server startup. - The server source files (
index.js→lib.js→path-validation.js) were examined to find the root cause.
Root Cause
In path-validation.js, the function isPathWithinAllowedDirectories() checks subdirectory membership with:
return normalizedPath.startsWith(normalizedDir + path.sep);UNC share roots are filesystem roots (like C:\) and retain their trailing backslash after normalization: \\server\share\. This creates a double trailing backslash (\\server\share\\) that never matches real paths. The code had special handling for drive roots like C:\ but not for UNC roots.
The Fix
Replace the problematic line with:
const dirWithSep = normalizedDir.endsWith(path.sep) ? normalizedDir : normalizedDir + path.sep;
return normalizedPath.startsWith(dirWithSep);Apply the patch with this PowerShell one-liner:
$file = "$env:APPDATA\Claude\Claude Extensions\ant.dir.ant.anthropic.filesystem\node_modules\@modelcontextprotocol\server-filesystem\dist\path-validation.js"
Copy-Item $file "$HOME\Desktop\path-validation.js.backup"
$content = Get-Content $file -Raw
$content = $content.Replace(
'return normalizedPath.startsWith(normalizedDir + path.sep);',
'const dirWithSep = normalizedDir.endsWith(path.sep) ? normalizedDir : normalizedDir + path.sep; return normalizedPath.startsWith(dirWithSep);'
)
[System.IO.File]::WriteAllText($file, $content)Then fully quit and restart Claude Desktop. Claude tested the fix itself using MCP tools after restarting—listing subdirectories and writing a test file to confirm functionality.
Note: This patch will be overwritten if the extension auto-updates. The fix should be implemented upstream in @modelcontextprotocol/server-filesystem. Related GitHub issues: #1838, #470.
📖 Read the full source: r/ClaudeAI
👀 See Also

Claudigotchi: Physical Tamagotchi Device That Feeds on Claude Code Activity
Claudigotchi is a physical desktop creature running on an ESP32 with an LCD screen that connects to Claude Code via a plugin. The device's hunger system responds to coding activity, with visual states and sound effects that escalate when Claude is left idle.

Introducing cltree: A File Tree TUI for Claude Code
cltree is a split-pane TUI that displays your project file tree in real-time alongside Claude Code, showing the current working directory, hiding noise, and allowing all keystrokes to pass through.

Self-Hosted Contextual Bandit in Rust: Syntra & Lycan for Adaptive Decision Systems
Two open-source projects: Lycan (graph execution language with strategy nodes and learned weights) and Syntra (Docker/API appliance serving compiled Lycan capsules). Found data pipeline bugs before runtime bugs when dogfooding on an AI stock-debate product.

Claude Code v2.1.143: Plugin Dependency Enforcement, PowerShell Defaults, and Background Session Fixes
Anthropic released Claude Code v2.1.143 with plugin dependency enforcement, PowerShell -ExecutionPolicy Bypass, new worktree isolation option, and numerous fixes for background sessions, Windows Terminal, and macOS file access.