This release includes 1 security fix for security teams reviewing exposed deployments.
Affected surfaces
Summary
AI summaryFixed isolation: 'worktree' subagents running git‑mutating commands against the main repo checkout instead of their own isolated worktree.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Medium |
Adds startup warning for Write/NotebookEdit/Glob permission rules, recommending Edit or Read instead Adds startup warning for Write/NotebookEdit/Glob permission rules, recommending Edit or Read instead Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Security | Medium |
Hardens Agent tool against indirect prompt injection via content read by a subagent Hardens Agent tool against indirect prompt injection via content read by a subagent Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Feature | Medium |
Auto mode now defaults permission classifier to Sonnet 5 for external sessions, validated on first request and pinned Auto mode now defaults permission classifier to Sonnet 5 for external sessions, validated on first request and pinned Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Feature | Low |
Adds live elapsed-time counter to collapsed tool summary line Adds live elapsed-time counter to collapsed tool summary line Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Low |
Improves Bash/PowerShell timeout message to distinguish command hang from explicit background request Improves Bash/PowerShell timeout message to distinguish command hang from explicit background request Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Feature | Low |
Enhances bundled dataviz skill's chart color validation using perceptual OKLab differences and recalibrated color‑blindness thresholds Enhances bundled dataviz skill's chart color validation using perceptual OKLab differences and recalibrated color‑blindness thresholds Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Feature | Low |
Announces permission mode changes aloud in screen‑reader mode when cycling with Shift+Tab Announces permission mode changes aloud in screen‑reader mode when cycling with Shift+Tab Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Bugfix | Medium |
Fixes ultracode keyword opt-in firing on non-human-originated input such as webhook payloads and relayed PR comments Fixes ultracode keyword opt-in firing on non-human-originated input such as webhook payloads and relayed PR comments Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Fixes crash telemetry leaking rendered text fragment when UI component returns content outside styled element Fixes crash telemetry leaking rendered text fragment when UI component returns content outside styled element Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Fixes paste markers leaking stray È/É characters into external editors opened from Claude Code Fixes paste markers leaking stray È/É characters into external editors opened from Claude Code Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Fixes session crash when tool result renderer returns numeric bigint or plain text instead of UI element Fixes session crash when tool result renderer returns numeric bigint or plain text instead of UI element Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Fixes Claude assuming `cd` took effect after command moved to background; result now states working directory unchanged Fixes Claude assuming `cd` took effect after command moved to background; result now states working directory unchanged Source: llm_adapter@2026-07-15 Confidence: low |
— |
| Bugfix | Medium |
Fixes isolation: 'worktree' subagents running git-mutating commands against main repo checkout Fixes isolation: 'worktree' subagents running git-mutating commands against main repo checkout Source: llm_adapter@2026-07-15 Confidence: low |
— |
| Bugfix | Medium |
Fixes `claude attach` failing with "job not found" or "agent is still starting" errors during session transitions Fixes `claude attach` failing with "job not found" or "agent is still starting" errors during session transitions Source: llm_adapter@2026-07-15 Confidence: low |
— |
| Bugfix | Medium |
Fixes hook callback timeout misreported as user rejection causing unattended sessions to stop and wait Fixes hook callback timeout misreported as user rejection causing unattended sessions to stop and wait Source: llm_adapter@2026-07-15 Confidence: low |
— |
| Bugfix | Medium |
Fixes plugin-provided MCP servers being torn down when MCP servers are re-synced mid-session Fixes plugin-provided MCP servers being torn down when MCP servers are re-synced mid-session Source: llm_adapter@2026-07-15 Confidence: low |
— |
| Bugfix | Medium |
Prevents plugin cache writes from leaving temp files on failure and failing on locked‑file renames on Windows/network filesystems Prevents plugin cache writes from leaving temp files on failure and failing on locked‑file renames on Windows/network filesystems Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Bugfix | Medium |
Releases lingering `git worktree lock` when killed background sessions leave it behind, via periodic sweep Releases lingering `git worktree lock` when killed background sessions leave it behind, via periodic sweep Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Bugfix | Low |
Ensures `cd` command in background reports working directory unchanged Ensures `cd` command in background reports working directory unchanged Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Bugfix | Low |
Fixes plan approvals without edits being incorrectly labeled "(edited by user)" and overwriting the plan file with stale data Fixes plan approvals without edits being incorrectly labeled "(edited by user)" and overwriting the plan file with stale data Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Bugfix | Low |
Ensures `/doctor` proposes auto‑mode default on Bedrock, Vertex, and Foundry even when opt‑in is no longer required Ensures `/doctor` proposes auto‑mode default on Bedrock, Vertex, and Foundry even when opt‑in is no longer required Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Bugfix | Low |
Corrects Grep content mode from falsely claiming "No matches found" after paginating past results Corrects Grep content mode from falsely claiming "No matches found" after paginating past results Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Bugfix | Low |
Preserves unmatched $1/$2 positional placeholders in skills and commands instead of silently stripping them Preserves unmatched $1/$2 positional placeholders in skills and commands instead of silently stripping them Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Bugfix | Low |
Stops background workers from crash‑looping when a client resets its connection to the background service Stops background workers from crash‑looping when a client resets its connection to the background service Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Bugfix | Low |
Ensures `claude agents --effort ultracode` reaches dispatched sessions by no longer dropping the value silently Ensures `claude agents --effort ultracode` reaches dispatched sessions by no longer dropping the value silently Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Bugfix | Low |
Prevents pressing ← from opening the agents view while losing the task tracker when returning to a session Prevents pressing ← from opening the agents view while losing the task tracker when returning to a session Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Bugfix | Low |
Clears pasted images from abandoned reply drafts in the agents dashboard after session deletion Clears pasted images from abandoned reply drafts in the agents dashboard after session deletion Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Bugfix | Low |
Starts SDK MCP servers registered via `initialize` control request immediately instead of waiting until the next turn Starts SDK MCP servers registered via `initialize` control request immediately instead of waiting until the next turn Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Bugfix | Low |
Eliminates overlapping ghost frames when returning to agents view from a session with CLAUDE_CODE_DISABLE_ALTERNATE_SCREEN=1 Eliminates overlapping ghost frames when returning to agents view from a session with CLAUDE_CODE_DISABLE_ALTERNATE_SCREEN=1 Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Bugfix | Low |
Reconciles late‑appearing `.claude/*` symlinks into the sandbox deny‑write list Reconciles late‑appearing `.claude/*` symlinks into the sandbox deny‑write list Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Bugfix | Low |
Produces explicit error when MEMORY.md index writes exceed read limit instead of silent truncation Produces explicit error when MEMORY.md index writes exceed read limit instead of silent truncation Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
Full changelog
What's changed
- Added a live elapsed-time counter to the collapsed tool summary line so long-running tool calls visibly tick instead of looking stuck
- Added a startup warning for
Write(path),NotebookEdit(path), andGlob(path)permission rules — useEdit(path)orRead(path)instead - Fixed
isolation: 'worktree'subagents being able to run git-mutating commands against the main repo checkout instead of their own isolated worktree - Fixed the
ultracodekeyword opt-in firing on non-human-originated input such as webhook payloads and relayed PR comments - Fixed a rendered text fragment leaking into crash telemetry when a UI component returned content outside a styled text element
- Fixed paste markers leaking into external editors opened from Claude Code, which could appear as stray È/É characters around pasted text
- Fixed
claude attachsometimes failing with "job not found" or "agent is still starting" errors during session transitions — attach now waits for the daemon to settle, and terminal resizes during a slow attach are applied once it completes - Fixed a session crash when a tool's result renderer returned a numeric bigint value or plain text instead of a UI element
- Fixed a hook callback timeout being misreported to the model as a user rejection, which made unattended sessions stop and wait
- Fixed Claude assuming a
cdtook effect after its command was moved to the background; the tool result now states the working directory is unchanged - Fixed plugin-provided MCP servers being torn down when MCP servers are re-synced mid-session
- Fixed plan approvals without edits being labeled "(edited by user)" and overwriting the plan file with a stale snapshot
- Fixed
/doctorskipping its auto-mode-default proposal on Bedrock, Vertex, and Foundry, where auto mode no longer needs an opt-in - Fixed Grep content mode claiming "No matches found" when paginating past the end of results
- Fixed unmatched
$1/$2positional placeholders in skills and commands being silently stripped; they are now preserved verbatim - Fixed plugin cache writes leaving temp files behind on failure and failing on locked-file renames on Windows and network filesystems
- Fixed background workers crash-looping when a client resets its connection to the background service
- Fixed
claude agents --effort ultracodenot reaching dispatched sessions; the value was silently dropped - Fixed pressing ← to open the agents view dropping the task tracker when returning to the session
- Fixed the agents dashboard retaining pasted images from abandoned reply drafts after their session was deleted
- Fixed killed background sessions leaving a permanent
git worktree lockbehind; the periodic sweep now releases locks whose owning process is gone - Fixed SDK MCP servers registered via an
initializecontrol request waiting until the next turn to start connecting - Fixed returning to the agents view from a session leaving overlapping ghost frames with
CLAUDE_CODE_DISABLE_ALTERNATE_SCREEN=1 - Fixed late-appearing
.claude/*symlinks not being reconciled into the sandbox deny-write list - Hardened the Agent tool against indirect prompt injection via content a subagent read
- Improved the Bash/PowerShell tool message when a command hits its timeout and is auto-backgrounded, so the model can distinguish a hang from an explicit background request
- Improved auto mode: the permission classifier now defaults to Sonnet 5 for external sessions, validated on the session's first request and pinned for the session
- Improved the bundled dataviz skill's chart color validation with perceptual OKLab color difference and recalibrated color-blindness thresholds
- Memory writes that leave a MEMORY.md index over its read limit now produce an explicit error instead of silent truncation
- Screen reader mode now announces permission mode changes aloud when cycling modes with Shift+Tab
- The agents footer hint now shows how many background agents are waiting on your input, with a brief color emphasis when the count changes
- Agent view: the session you pressed ← from stays visibly marked even after mouse hover or arrow keys move the selection
- Fable temporarily shows as unavailable in the advisor picker while a server-side issue causing Fable advisor failures is fixed
Security Fixes
- Hardened Agent tool against indirect prompt injection via content a subagent read
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About claude-code
All releases →Related context
Earlier breaking changes
- v2.1.215 Claude no longer automatically runs /verify and /code-review skills
- v2.1.160 Renames dynamic‑workflow trigger keyword from `workflow` to `ultracode`; `workflow` no longer triggers a run
- v2.1.160 Deprecates and removes the `CLAUDE_CODE_OPUS_4_6_FAST_MODE_OVERRIDE` environment variable; it is now a no‑op
- v2.1.147 Renames /simplify to /code-review; removes cleanup-and-fix behavior.
Beta — feedback welcome: [email protected]