STUPID-2026-0123

Claude Code's rm -rf/Remove-Item followed an NTFS junction out of a pnpm worktree and wiped a user's Documents, Downloads, Pictures and two unpushed commits (GitHub #29249)

8.5high
February 27, 2026VerifiedReproducible
  1. Instruction given

    Remove two git worktrees (variant-a and variant-b) from a pnpm monorepo on Windows.

  2. Expected behavior

    Delete only the contents of the two worktree directories, leaving the rest of the filesystem — including unrelated folders pnpm had linked into node_modules via NTFS junctions — untouched.

  3. Actual behavior

    Claude Code ran `Remove-Item -Recurse -Force` (and, in Git Bash/MSYS, `rm -rf`) directly on the worktree paths. pnpm had populated each worktree's node_modules with NTFS junctions (not symlinks) pointing elsewhere on the disk, and both Windows PowerShell's Remove-Item and MSYS's rm follow junctions into their targets rather than removing the link itself — a gap patched in PowerShell Core 6+ but never backported to the Windows PowerShell 5.1 that Claude Code's Bash tool shells out to. The deletion silently escaped the worktree and recursed into the junction targets.

  4. Damage

    The user's entire Documents, Downloads, Music, Pictures, Videos and Favorites folders were permanently deleted (both Remove-Item -Force and rm -rf bypass the Recycle Bin), along with parts of two other projects (WAOK-MONOREPO and WAOK-LEGACY). WAOK-MONOREPO was recoverable by re-cloning, but two unpushed commits and all uncommitted working changes were lost. The reporter confirmed the same prompt reproduces the data loss every time and filed the issue with the `has-repro` and `data-loss` labels; it was closed as not planned with no fix shipped.

On February 27, 2026, a Claude Code user on Windows filed GitHub issue #29249 after asking the agent to remove two git worktrees, `variant-a` and `variant-b`, from a pnpm monorepo. Claude Code executed `Remove-Item -Recurse -Force` (and, via its MSYS-based Bash tool, `rm -rf`) directly on the worktree paths. pnpm had wired each worktree's `node_modules` with NTFS junctions rather than symlinks to share packages across the monorepo's workspaces, and both the Windows PowerShell 5.1 build Claude Code's tooling invokes and MSYS's `rm` follow junctions into their real targets instead of deleting the link — a bug already patched in PowerShell Core 6+ (tracked upstream in PowerShell/PowerShell#621) but never backported to the Windows PowerShell shipped with the OS. The recursive delete escaped the worktree entirely and tore through the junction targets: the user's whole Documents, Downloads, Music, Pictures, Videos and Favorites folders were gone, all of it bypassing the Recycle Bin since both `Remove-Item -Force` and `rm -rf` delete permanently. Two other projects, WAOK-MONOREPO and WAOK-LEGACY, were also partially wiped; WAOK-MONOREPO was recoverable by re-cloning from the remote, but two unpushed commits and all uncommitted working-tree changes could not be recovered. The user confirmed the exact same prompt and setup reproduce the deletion every time, and listed the safe alternatives Claude Code could have used instead — `cmd.exe /c "rmdir /S /Q <path>"`, `git worktree remove`, or simply requesting confirmation before a recursive delete on Windows. The issue was filed with the `bug`, `data-loss`, and `has-repro` labels and closed as not planned, with no fix or mitigation shipped.

Classification

Failure mode
Destructive Action
Domain
Infra

Related incidents

Get told when an agent breaks something

We document AI agent failures daily, severity-scored against a published scale. When one lands at 7.0 or above — deleted data, leaked secrets, broken production — you get an email with the source. When nothing does, you get nothing.

This database is callable over MCP — query it from inside your agent.