Skip to content

claude-code

Claude Code v2.1.214 closes a Bash permission bypass

Claude News

The v2.1.214 patch focuses on command permission checks. The headline fix: a permission bypass in Windows PowerShell 5.1 sessions is gone. Commands longer than 10,000 characters now always ask for confirmation instead of running automatically.

A few more hardening changes:

• Bash checks no longer treat zsh variable substitutions inside [[ ]] comparisons as inert text, so those commands now require confirmation • An Edit(src/**) rule no longer approved writes to nested dir/ directories across the whole tree • Remote sessions could pass checks before the local confirmation dialog was answered

The patch also adds an EndConversation tool that lets Claude terminate sessions on especially aggressive behavior and jailbreak attempts, the same way claude.ai has since 2025.

Related stories

  1. Claude Code v2.1.217: subagent caps and a memory fix
  2. Claude Code v2.1.215 stops auto-running /verify and /code-review
  3. Claude Code v2.1.212: /fork now spawns a background session
  4. Claude Code 2.1.282 ignores telemetry set by project files
  5. Claude Code opens network hosts one command at a time
  6. Claude Code 2.1.223 patches a Bash permission bypass

Comments

No comments yet. Be the first.

Join the conversation

Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.

We only use your name and avatar from Google. We never store your email address.