Skip to content

claude-code

v2.1.210 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Affected surfaces

auth rbac

Summary

AI summary

Fixed isolation: 'worktree' subagents running git‑mutating commands against the main repo checkout instead of their own isolated worktree.

Changes in this release

Security Medium

Adds startup warning for Write/NotebookEdit/Glob permission rules, recommending Edit or Read instead

Adds startup warning for Write/NotebookEdit/Glob permission rules, recommending Edit or Read instead

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

Security Medium

Hardens Agent tool against indirect prompt injection via content read by a subagent

Hardens Agent tool against indirect prompt injection via content read by a subagent

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

Feature Medium

Auto mode now defaults permission classifier to Sonnet 5 for external sessions, validated on first request and pinned

Auto mode now defaults permission classifier to Sonnet 5 for external sessions, validated on first request and pinned

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

Feature Low

Adds live elapsed-time counter to collapsed tool summary line

Adds live elapsed-time counter to collapsed tool summary line

Source: llm_adapter@2026-07-15

Confidence: high

Feature Low

Improves Bash/PowerShell timeout message to distinguish command hang from explicit background request

Improves Bash/PowerShell timeout message to distinguish command hang from explicit background request

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

Feature Low

Enhances bundled dataviz skill's chart color validation using perceptual OKLab differences and recalibrated color‑blindness thresholds

Enhances bundled dataviz skill's chart color validation using perceptual OKLab differences and recalibrated color‑blindness thresholds

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

Feature Low

Announces permission mode changes aloud in screen‑reader mode when cycling with Shift+Tab

Announces permission mode changes aloud in screen‑reader mode when cycling with Shift+Tab

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

Bugfix Medium

Fixes ultracode keyword opt-in firing on non-human-originated input such as webhook payloads and relayed PR comments

Fixes ultracode keyword opt-in firing on non-human-originated input such as webhook payloads and relayed PR comments

Source: llm_adapter@2026-07-15

Confidence: high

Bugfix Medium

Fixes crash telemetry leaking rendered text fragment when UI component returns content outside styled element

Fixes crash telemetry leaking rendered text fragment when UI component returns content outside styled element

Source: llm_adapter@2026-07-15

Confidence: high

Bugfix Medium

Fixes paste markers leaking stray È/É characters into external editors opened from Claude Code

Fixes paste markers leaking stray È/É characters into external editors opened from Claude Code

Source: llm_adapter@2026-07-15

Confidence: high

Bugfix Medium

Fixes session crash when tool result renderer returns numeric bigint or plain text instead of UI element

Fixes session crash when tool result renderer returns numeric bigint or plain text instead of UI element

Source: llm_adapter@2026-07-15

Confidence: high

Bugfix Medium

Fixes Claude assuming `cd` took effect after command moved to background; result now states working directory unchanged

Fixes Claude assuming `cd` took effect after command moved to background; result now states working directory unchanged

Source: llm_adapter@2026-07-15

Confidence: low

Bugfix Medium

Fixes isolation: 'worktree' subagents running git-mutating commands against main repo checkout

Fixes isolation: 'worktree' subagents running git-mutating commands against main repo checkout

Source: llm_adapter@2026-07-15

Confidence: low

Bugfix Medium

Fixes `claude attach` failing with "job not found" or "agent is still starting" errors during session transitions

Fixes `claude attach` failing with "job not found" or "agent is still starting" errors during session transitions

Source: llm_adapter@2026-07-15

Confidence: low

Bugfix Medium

Fixes hook callback timeout misreported as user rejection causing unattended sessions to stop and wait

Fixes hook callback timeout misreported as user rejection causing unattended sessions to stop and wait

Source: llm_adapter@2026-07-15

Confidence: low

Bugfix Medium

Fixes plugin-provided MCP servers being torn down when MCP servers are re-synced mid-session

Fixes plugin-provided MCP servers being torn down when MCP servers are re-synced mid-session

Source: llm_adapter@2026-07-15

Confidence: low

Bugfix Medium

Prevents plugin cache writes from leaving temp files on failure and failing on locked‑file renames on Windows/network filesystems

Prevents plugin cache writes from leaving temp files on failure and failing on locked‑file renames on Windows/network filesystems

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

Bugfix Medium

Releases lingering `git worktree lock` when killed background sessions leave it behind, via periodic sweep

Releases lingering `git worktree lock` when killed background sessions leave it behind, via periodic sweep

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

Bugfix Low

Ensures `cd` command in background reports working directory unchanged

Ensures `cd` command in background reports working directory unchanged

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

Bugfix Low

Fixes plan approvals without edits being incorrectly labeled "(edited by user)" and overwriting the plan file with stale data

Fixes plan approvals without edits being incorrectly labeled "(edited by user)" and overwriting the plan file with stale data

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

Bugfix Low

Ensures `/doctor` proposes auto‑mode default on Bedrock, Vertex, and Foundry even when opt‑in is no longer required

Ensures `/doctor` proposes auto‑mode default on Bedrock, Vertex, and Foundry even when opt‑in is no longer required

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

Bugfix Low

Corrects Grep content mode from falsely claiming "No matches found" after paginating past results

Corrects Grep content mode from falsely claiming "No matches found" after paginating past results

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

Bugfix Low

Preserves unmatched $1/$2 positional placeholders in skills and commands instead of silently stripping them

Preserves unmatched $1/$2 positional placeholders in skills and commands instead of silently stripping them

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

Bugfix Low

Stops background workers from crash‑looping when a client resets its connection to the background service

Stops background workers from crash‑looping when a client resets its connection to the background service

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

Bugfix Low

Ensures `claude agents --effort ultracode` reaches dispatched sessions by no longer dropping the value silently

Ensures `claude agents --effort ultracode` reaches dispatched sessions by no longer dropping the value silently

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

Bugfix Low

Prevents pressing ← from opening the agents view while losing the task tracker when returning to a session

Prevents pressing ← from opening the agents view while losing the task tracker when returning to a session

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

Bugfix Low

Clears pasted images from abandoned reply drafts in the agents dashboard after session deletion

Clears pasted images from abandoned reply drafts in the agents dashboard after session deletion

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

Bugfix Low

Starts SDK MCP servers registered via `initialize` control request immediately instead of waiting until the next turn

Starts SDK MCP servers registered via `initialize` control request immediately instead of waiting until the next turn

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

Bugfix Low

Eliminates overlapping ghost frames when returning to agents view from a session with CLAUDE_CODE_DISABLE_ALTERNATE_SCREEN=1

Eliminates overlapping ghost frames when returning to agents view from a session with CLAUDE_CODE_DISABLE_ALTERNATE_SCREEN=1

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

Bugfix Low

Reconciles late‑appearing `.claude/*` symlinks into the sandbox deny‑write list

Reconciles late‑appearing `.claude/*` symlinks into the sandbox deny‑write list

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

Bugfix Low

Produces explicit error when MEMORY.md index writes exceed read limit instead of silent truncation

Produces explicit error when MEMORY.md index writes exceed read limit instead of silent truncation

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

Full changelog

What's changed

  • Added a live elapsed-time counter to the collapsed tool summary line so long-running tool calls visibly tick instead of looking stuck
  • Added a startup warning for Write(path), NotebookEdit(path), and Glob(path) permission rules — use Edit(path) or Read(path) instead
  • Fixed isolation: 'worktree' subagents being able to run git-mutating commands against the main repo checkout instead of their own isolated worktree
  • Fixed the ultracode keyword opt-in firing on non-human-originated input such as webhook payloads and relayed PR comments
  • Fixed a rendered text fragment leaking into crash telemetry when a UI component returned content outside a styled text element
  • Fixed paste markers leaking into external editors opened from Claude Code, which could appear as stray È/É characters around pasted text
  • Fixed claude attach sometimes failing with "job not found" or "agent is still starting" errors during session transitions — attach now waits for the daemon to settle, and terminal resizes during a slow attach are applied once it completes
  • Fixed a session crash when a tool's result renderer returned a numeric bigint value or plain text instead of a UI element
  • Fixed a hook callback timeout being misreported to the model as a user rejection, which made unattended sessions stop and wait
  • Fixed Claude assuming a cd took effect after its command was moved to the background; the tool result now states the working directory is unchanged
  • Fixed plugin-provided MCP servers being torn down when MCP servers are re-synced mid-session
  • Fixed plan approvals without edits being labeled "(edited by user)" and overwriting the plan file with a stale snapshot
  • Fixed /doctor skipping its auto-mode-default proposal on Bedrock, Vertex, and Foundry, where auto mode no longer needs an opt-in
  • Fixed Grep content mode claiming "No matches found" when paginating past the end of results
  • Fixed unmatched $1/$2 positional placeholders in skills and commands being silently stripped; they are now preserved verbatim
  • Fixed plugin cache writes leaving temp files behind on failure and failing on locked-file renames on Windows and network filesystems
  • Fixed background workers crash-looping when a client resets its connection to the background service
  • Fixed claude agents --effort ultracode not reaching dispatched sessions; the value was silently dropped
  • Fixed pressing ← to open the agents view dropping the task tracker when returning to the session
  • Fixed the agents dashboard retaining pasted images from abandoned reply drafts after their session was deleted
  • Fixed killed background sessions leaving a permanent git worktree lock behind; the periodic sweep now releases locks whose owning process is gone
  • Fixed SDK MCP servers registered via an initialize control request waiting until the next turn to start connecting
  • Fixed returning to the agents view from a session leaving overlapping ghost frames with CLAUDE_CODE_DISABLE_ALTERNATE_SCREEN=1
  • Fixed late-appearing .claude/* symlinks not being reconciled into the sandbox deny-write list
  • Hardened the Agent tool against indirect prompt injection via content a subagent read
  • Improved the Bash/PowerShell tool message when a command hits its timeout and is auto-backgrounded, so the model can distinguish a hang from an explicit background request
  • Improved auto mode: the permission classifier now defaults to Sonnet 5 for external sessions, validated on the session's first request and pinned for the session
  • Improved the bundled dataviz skill's chart color validation with perceptual OKLab color difference and recalibrated color-blindness thresholds
  • Memory writes that leave a MEMORY.md index over its read limit now produce an explicit error instead of silent truncation
  • Screen reader mode now announces permission mode changes aloud when cycling modes with Shift+Tab
  • The agents footer hint now shows how many background agents are waiting on your input, with a brief color emphasis when the count changes
  • Agent view: the session you pressed ← from stays visibly marked even after mouse hover or arrow keys move the selection
  • Fable temporarily shows as unavailable in the advisor picker while a server-side issue causing Fable advisor failures is fixed

Security Fixes

  • Hardened Agent tool against indirect prompt injection via content a subagent read

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track claude-code

Get notified when new releases ship.

Sign up free

About claude-code

All releases →

Related context

Earlier breaking changes

  • v2.1.215 Claude no longer automatically runs /verify and /code-review skills
  • v2.1.160 Renames dynamic‑workflow trigger keyword from `workflow` to `ultracode`; `workflow` no longer triggers a run
  • v2.1.160 Deprecates and removes the `CLAUDE_CODE_OPUS_4_6_FAST_MODE_OVERRIDE` environment variable; it is now a no‑op
  • v2.1.147 Renames /simplify to /code-review; removes cleanup-and-fix behavior.

Beta — feedback welcome: [email protected]