Claude Code 2.1.205: security and agent fixes

Version 2.1.205 is out. The main changes:
• A new auto mode rule blocks edits to the session transcript file • Auto mode now asks for confirmation before running rm -rf on a variable it can't resolve from context • Background task notifications state explicitly that no human was involved, so fake approvals can't slip into the transcript • Auto-update binaries now stream to disk instead of buffering in memory, cutting peak usage by roughly 400 MB • Fixed deletion of files outside the worktree on Windows when an NTFS junction or symlink sits inside
The MCP server names "Claude Browser" and "Claude Preview" are now reserved ahead of a Claude Desktop panel rename; user servers can't register under those names.
Related stories
- Claude Code 2.1.282 ignores telemetry set by project files
- Claude Code opens network hosts one command at a time
- Claude Code 2.1.223 patches a Bash permission bypass
- Worktree isolation was leaking git commands into the main copy
- Claude Code 2.1.221: permission bypass fixed, Focus view in VSCode, credential masking
- Claude Code v2.1.214 closes a Bash permission bypass
Comments
No comments yet. Be the first.
Join the conversation
Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.
