This release includes 1 security fix for security teams reviewing exposed deployments.
Affected surfaces
Summary
AI summaryAdded safe‑mode flag, /cd command, and bundled‑skill disable option.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | High |
Prevents untrusted project settings from setting OTEL client‑certificate paths without trust confirmation Prevents untrusted project settings from setting OTEL client‑certificate paths without trust confirmation Source: granite4.1:30b@2026-06-09-audit Confidence: low |
— |
| Feature | Low |
Adds --safe-mode flag and CLAUDE_CODE_SAFE_MODE env var to disable all customizations for troubleshooting Adds --safe-mode flag and CLAUDE_CODE_SAFE_MODE env var to disable all customizations for troubleshooting Source: llm_adapter@2026-06-09 Confidence: high |
— |
| Feature | Low |
Adds /cd command to move a session to a new working directory without breaking the prompt cache Adds /cd command to move a session to a new working directory without breaking the prompt cache Source: llm_adapter@2026-06-09 Confidence: high |
— |
| Feature | Low |
Adds disableBundledSkills setting and CLAUDE_CODE_DISABLE_BUNDLED_SKILLS env var to hide bundled skills, workflows, and slash commands Adds disableBundledSkills setting and CLAUDE_CODE_DISABLE_BUNDLED_SKILLS env var to hide bundled skills, workflows, and slash commands Source: llm_adapter@2026-06-09 Confidence: high |
— |
| Feature | Low |
/workflows now opens immediately even while a turn is in progress /workflows now opens immediately even while a turn is in progress Source: granite4.1:30b@2026-06-09-audit Confidence: low |
— |
| Feature | Low |
Restores default 5‑minute idle timeout on Vertex/Foundry; set API_FORCE_IDLE_TIMEOUT=0 to opt out Restores default 5‑minute idle timeout on Vertex/Foundry; set API_FORCE_IDLE_TIMEOUT=0 to opt out Source: granite4.1:30b@2026-06-09-audit Confidence: low |
— |
| Feature | Low |
Preserves flags (e.g., --ide, --chrome) across retire→wake for background sessions and hardens respawn validation Preserves flags (e.g., --ide, --chrome) across retire→wake for background sessions and hardens respawn validation Source: granite4.1:30b@2026-06-09-audit Confidence: low |
— |
| Feature | Low |
Scales the “CLAUDE.md is too long” warning threshold with the model’s context window size Scales the “CLAUDE.md is too long” warning threshold with the model’s context window size Source: granite4.1:30b@2026-06-09-audit Confidence: low |
— |
| Feature | Low |
Improves color contrast for skill tags in the slash‑command menu Improves color contrast for skill tags in the slash‑command menu Source: granite4.1:30b@2026-06-09-audit Confidence: low |
— |
| Feature | Low |
Explains where to add a payment method for Apple/Google‑billed subscribers without one when claiming promo credits Explains where to add a payment method for Apple/Google‑billed subscribers without one when claiming promo credits Source: granite4.1:30b@2026-06-09-audit Confidence: low |
— |
| Feature | Low |
Adds a tip suggesting `claude agents` when running multiple concurrent sessions Adds a tip suggesting `claude agents` when running multiple concurrent sessions Source: granite4.1:30b@2026-06-09-audit Confidence: low |
— |
| Performance | Low |
Reduces CPU usage during response streaming and spinner animations Reduces CPU usage during response streaming and spinner animations Source: granite4.1:30b@2026-06-09-audit Confidence: low |
— |
| Bugfix | Medium |
Fixes Up/Down arrows jumping past wrapped rows; they now move through each visual row first before history recall Fixes Up/Down arrows jumping past wrapped rows; they now move through each visual row first before history recall Source: llm_adapter@2026-06-09 Confidence: high |
— |
| Bugfix | Medium |
Fixes ~30‑50 ms UI stall at the start of each turn for macOS users logged in with claude.ai credentials Fixes ~30‑50 ms UI stall at the start of each turn for macOS users logged in with claude.ai credentials Source: llm_adapter@2026-06-09 Confidence: high |
— |
| Bugfix | Medium |
Fixes `claude -p` being slow or appearing to hang on Windows due to slash‑command/skill scan regression Fixes `claude -p` being slow or appearing to hang on Windows due to slash‑command/skill scan regression Source: llm_adapter@2026-06-09 Confidence: high |
— |
| Bugfix | Medium |
Fixes Remote Control getting stuck on “reconnecting” after session reattachment when OAuth token refresh occurs simultaneously Fixes Remote Control getting stuck on “reconnecting” after session reattachment when OAuth token refresh occurs simultaneously Source: llm_adapter@2026-06-09 Confidence: high |
— |
| Bugfix | Medium |
Fixes Git Credential Manager’s “Connect to GitHub” popup appearing on Windows startup without cached credentials Fixes Git Credential Manager’s “Connect to GitHub” popup appearing on Windows startup without cached credentials Source: llm_adapter@2026-06-09 Confidence: high |
— |
| Bugfix | Medium |
Fixes footer hints (e.g., “esc to interrupt”) not showing for users with a custom statusline Fixes footer hints (e.g., “esc to interrupt”) not showing for users with a custom statusline Source: llm_adapter@2026-06-09 Confidence: high |
— |
| Bugfix | Medium |
Fixes enterprise MCP policies not being enforced on reconnect, IDE‑typed configs, --mcp-config servers, and during cold starts without remote settings Fixes enterprise MCP policies not being enforced on reconnect, IDE‑typed configs, --mcp-config servers, and during cold starts without remote settings Source: llm_adapter@2026-06-09 Confidence: low |
— |
| Bugfix | Medium |
Fixes `claude agents --json` omitting blocked and just‑dispatched background sessions; adds `--all` flag and new `id`/`state` fields Fixes `claude agents --json` omitting blocked and just‑dispatched background sessions; adds `--all` flag and new `id`/`state` fields Source: granite4.1:30b@2026-06-09-audit Confidence: low |
— |
| Bugfix | Medium |
Ensures background agents respect project‑level `env` settings (e.g., ANTHROPIC_MODEL) when dispatched onto pre‑warmed workers Ensures background agents respect project‑level `env` settings (e.g., ANTHROPIC_MODEL) when dispatched onto pre‑warmed workers Source: granite4.1:30b@2026-06-09-audit Confidence: low |
— |
| Bugfix | Medium |
Applies valid policies and surfaces validation errors when remote‑managed settings contain an invalid entry, instead of dropping the whole payload Applies valid policies and surfaces validation errors when remote‑managed settings contain an invalid entry, instead of dropping the whole payload Source: granite4.1:30b@2026-06-09-audit Confidence: low |
— |
| Bugfix | Medium |
Informs background sessions that shared‑checkout edits are blocked until they enter a worktree, avoiding wasted rejected edits before EnterWorktree Informs background sessions that shared‑checkout edits are blocked until they enter a worktree, avoiding wasted rejected edits before EnterWorktree Source: granite4.1:30b@2026-06-09-audit Confidence: low |
— |
| Bugfix | Low |
Prevents stale permission dialogs from reappearing when reattaching to a remote session after worker death Prevents stale permission dialogs from reappearing when reattaching to a remote session after worker death Source: granite4.1:30b@2026-06-09-audit Confidence: low |
— |
| Bugfix | Low |
Fixes agents view leaving a garbled frame after navigating back from an agent on WSL in Windows Terminal Fixes agents view leaving a garbled frame after navigating back from an agent on WSL in Windows Terminal Source: granite4.1:30b@2026-06-09-audit Confidence: low |
— |
| Bugfix | Low |
Prevents MCPB plugin cache from being spuriously invalidated on Windows, avoiding unnecessary re‑extraction Prevents MCPB plugin cache from being spuriously invalidated on Windows, avoiding unnecessary re‑extraction Source: granite4.1:30b@2026-06-09-audit Confidence: low |
— |
| Bugfix | Low |
Cleans up accumulated `.in_use` PID lock files daily, removing stale markers from crashed sessions Cleans up accumulated `.in_use` PID lock files daily, removing stale markers from crashed sessions Source: granite4.1:30b@2026-06-09-audit Confidence: low |
— |
| Bugfix | Low |
Stops Windows auto‑updater from retrying within a session when claude.exe is held by another process Stops Windows auto‑updater from retrying within a session when claude.exe is held by another process Source: granite4.1:30b@2026-06-09-audit Confidence: low |
— |
Full changelog
What's changed
- Added
--safe-modeflag (andCLAUDE_CODE_SAFE_MODE) to start Claude Code with all customizations (CLAUDE.md, plugins, skills, hooks, MCP servers) disabled for troubleshooting - Added
/cdcommand to move a session to a new working directory without breaking the prompt cache mid-session - Added a
disableBundledSkillssetting andCLAUDE_CODE_DISABLE_BUNDLED_SKILLSenvironment variable to hide bundled skills, workflows, and built-in slash commands from the model - Fixed Up/Down arrows jumping to command history past the wrapped rows of a long input line — they now move through each visual row first, and history recall enters at the near edge
- Fixed enterprise managed MCP policies (
allowedMcpServers/deniedMcpServers) not being enforced on reconnect, IDE-typed configs,--mcp-configservers during the first session after install, or before remote settings loaded; also fixed slow cold starts for orgs without remote settings - Fixed a ~30-50ms UI stall at the start of each turn for macOS users logged in with claude.ai credentials
- Fixed
claude -pbeing slow or appearing to hang on Windows while waiting for the slash-command/skill scan (regression in 2.1.161) - Fixed Remote Control getting stuck on "reconnecting" after resuming a session when an OAuth token refresh happened at the same time
- Fixed Git Credential Manager's "Connect to GitHub" popup appearing on Windows at startup when background git commands ran without cached credentials
- Fixed footer hints (e.g. "esc to interrupt") not showing for users with a custom statusline
- Fixed stale permission and dialog prompts reappearing every time you reattached to a remote session whose worker had died while waiting on them
- Fixed
claude agents --jsonomitting blocked and just-dispatched background sessions; added--allto include completed sessions, plus newidandstatefields - Fixed agents view leaving a stale/garbled frame after navigating back from an agent on WSL in Windows Terminal
- Fixed background agents ignoring project-level settings
envvalues (e.g.ANTHROPIC_MODEL) when dispatched onto a pre-warmed worker - Fixed MCPB plugin cache being spuriously invalidated on Windows, causing unnecessary re-extraction
- Fixed plugin
.in_usePID lock files accumulating without bound; stale markers from crashed sessions are now swept once per day - Fixed untrusted project settings being able to set OTEL client-certificate paths without trust confirmation
/workflowsnow opens immediately even while a turn is in progress- Improved
TaskCreatereliability: malformed inputs are repaired automatically and validation errors for unloaded tools include the schema - Improved the error message shown when your organization has disabled API key authentication, with guidance based on where the active API key comes from
- Reduced CPU usage while responses stream and during spinner animations
- Restored a default 5-minute idle timeout on Vertex/Foundry so a stalled stream aborts instead of hanging indefinitely; set
API_FORCE_IDLE_TIMEOUT=0to opt out - Remote-managed settings with an invalid entry now apply their remaining valid policies and surface the validation error, instead of silently dropping the whole payload
- Background sessions now preserve
--ide,--chrome,--bare,--remote-control, and other flags across retire→wake, and respawn state validation was hardened - Background sessions are now told that shared-checkout edits are blocked until they enter a worktree, avoiding a wasted rejected edit before
EnterWorktree - The "CLAUDE.md is too long" warning threshold now scales with the model's context window
- Auto-updater on Windows now stops retrying within a session once
claude.exeis held by another process - Improved color contrast for skill tags in the slash-command menu
- Promo credit claims for Apple/Google-billed subscribers without a payment method now explain where to add one
- Added a tip suggesting
claude agentswhen running multiple concurrent sessions
Security Fixes
- Fixed untrusted project settings allowing OTEL client‑certificate paths without trust confirmation
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About claude-code
All releases →Related context
Earlier breaking changes
- v2.1.215 Claude no longer automatically runs /verify and /code-review skills
- v2.1.160 Renames dynamic‑workflow trigger keyword from `workflow` to `ultracode`; `workflow` no longer triggers a run
- v2.1.160 Deprecates and removes the `CLAUDE_CODE_OPUS_4_6_FAST_MODE_OVERRIDE` environment variable; it is now a no‑op
- v2.1.147 Renames /simplify to /code-review; removes cleanup-and-fix behavior.
Beta — feedback welcome: [email protected]