2.1.289: Security, stability, and rendering fixes
This release fixes multiple security vulnerabilities including unauthorized approval bypass for managed mods, plugin permission bypasses, and MCP server description rewriting. It also addresses terminal freezes with malformed script tags, file access denial rule bypasses via symlinks, authentication regression, and numerous plugin/mod rendering and session stability issues.
- Fixed a deny or ask rule on a nested part of a compound shell command not holding over a user-installed mod's approval on managed machines
- Fixed the terminal freezing on short code blocks with many unclosed
<script>tags or deeply nested${substitutions - Fixed
Readdeny rules not applying to files @-mentioned, changed, or selected in the IDE through a symlink - [VSCode] Reverted a 2.1.288 change to
claude auth statusthat may have made sign-outs more frequent - Improved how quickly large files open in a plugin code pane by laying the highlighted view out once at its final width
- Fixed
plugin list,plugin evalandplugin updateshowing a stale copy of a plugin installed from a local folder marketplace, and hot reload for a symlinked--plugin-dir - Fixed installed mods not loading in the first session after an upgrade
- Fixed a plugin's rows above the prompt showing a stale row while the Background tasks dialog was open in fullscreen
- Fixed plugin panes drawing nothing when a link used a localhost address, an
@in its path, an uppercase host or afile:path - Fixed a user-installed plugin being able to rewrite the descriptions of an organization-managed MCP server's sign-in tools
- Fixed a freeze or forced quit at launch when a plugin drew a Box with a border style the terminal does not know
- Fixed supervised and background sessions ending when a plugin's on-screen handler threw asynchronously
- Fixed sessions ending with an interface error when a plugin region with no height kept growing
- Fixed Bash deny and ask rules missing a command behind an environment variable prefix with an expanded value (e.g.
TZ="$HOME" rm -rf build) when the sandbox auto-allows commands - Fixed a Bash deny or ask rule being skipped under sandbox auto-allow when a bare variable assignment came before the command
- Fixed
claude plugin validateskipping the plugin when the folder also holds a marketplace manifest - Added
agent.spawnfor teammates, one agent id across plugin hook events, and idle and waiting states in$.agent.list() - Fixed sessions ending with "unrecoverable interface error" when a value a mod's
ui.renderhook wrote made a row throw while drawn; the engine now draws its own row instead - Fixed text with a tab, a stray escape and a C1 control, or a short text with a tab and CRLF line endings, drawing over the rows below it
- Fixed right-aligned content in a mod's pane or band drawing under the close mark or
[-], which now also keep one column in from the terminal's edge - Fixed a mod's
Clientthat fails while drawn taking down everything the mod drew around it; it now fails alone and raisesui.fault - Fixed
claude plugin validatefailing an Anthropic marketplace's own plugin and listing a cleanplugin.jsonin--json - Fixed a mod's band that fails to draw briefly telling the cards under it to step aside
- Fixed a failed plugin component showing
Erroror nothing as its reason when the failure carried no message - Improved the line a mod's author sees when its band or pane fails to draw: it names the mod and says nothing was drawn
- Fixed published artifact pages freezing or crashing the reader's browser tab on short code blocks with many unclosed
<script>tags - Fixed a mod's Client region staying failed for the whole session after the terminal threw while drawing it
Source: original entry ↗
More from Claude Code
Follow Claude Code to get its new changes in your feed and email digest.
Claude Code 2.1.293
Released version 2.1.293 with Claude Haiku 5.5 as the default Haiku model featuring 1M context window, expanded agent functionality with agentType and isDeferred fields, and numerous bug fixes across context management, MCP connections, vim mode, permissions, and cloud sessions.
Claude Code 2.1.292 Release
Claude Code 2.1.292 includes new features like marketplace source support for plugin installation, effort parameters for agent tools, and prompt caching for mods. This release also addresses numerous security fixes including permission bypass issues, file access restrictions, and cache tampering vulnerabilities, plus improvements to session handling, auto mode restoration, and various UI/UX fixes.
Fixed regressions with cloud sessions and message handling
Fixed a regression where cloud sessions could drop answers to permission prompts and another regression where the last messages of a session could be lost when quitting.