Claude Code 2.1.223 patches a Bash permission bypass

The release closes four permission holes. The worst: a specially crafted Bash command could hide part of itself from the permission check, and the same trick worked with tab characters and invisible Unicode inside the confirmation dialog, so what you approved wasn't what ran.
• Crafted Bash commands could conceal part of themselves from the permission check; tabs and invisible Unicode characters did the same in the confirmation prompt • Workflow scripts using dynamic import() executed code outside the sandbox • bypassPermissions set in an agent description ignored the enterprise policy blocking permission bypass • Managed settings now accept "owner/*" entries to allow or block every marketplace repo under a GitHub organization • A warning now appears when a subagent requests a restricted model and the parent model runs instead
Cloud sessions also show a /teleport hint with the command to continue the work locally.
Related stories
- Worktree isolation was leaking git commands into the main copy
- Claude Code 2.1.227 stops pitching credits to Max subscribers
- Spend-limit errors now name the limit and the reset time
- Claude Code sessions can now run on your own machines
- Claude Code 2.1.282 ignores telemetry set by project files
- Claude Code opens network hosts one command at a time
Comments
No comments yet. Be the first.
Join the conversation
Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.
