Vulnerability in Claude Dynamic Workflows access controls

A bug was found in Claude Code version 2.1.168 related to Dynamic Workflows. Subagents launched under Dynamic Workflows inherit the user's command confirmation settings from their current session, which contradicts the documentation.
According to the official description, subagents should operate in acceptEdits mode, limiting file editing. In practice, they can gain Auto or BypassPermissions access. This creates a risk of unauthorized command execution, MCP calls, and protected file editing.
The Dynamic Workflows feature is set to become available to all users on June 8, 2026. Organizations can disable it in Claude Code settings by setting disableWorkflows: true in the settings.json file or through the role settings panel.
Related stories
- Claude's Dynamic Workflows architecture
- Anthropic introduces Dynamic Workflows in Claude Code
- Claude Code 2.1.282 ignores telemetry set by project files
- Two Claude Code sessions ate 32% of a team's bill
- One git call let a repo escape the Claude Code sandbox
- Claude Code opens network hosts one command at a time
Comments
No comments yet. Be the first.
Join the conversation
Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.
