Claude Code Fixes Multiple Permission Bypass Bugs, Adds Abusive Session Termination
ashwin-ant · ghdev · 2026-07-18
Anthropic releases Claude Code v2.1.214, focusing on fixing several security risks that could lead to unauthorized operations and improving usability.
- Security Fixes: Corrected an issue where dir/ rules auto-approved writes to nested directories; fixed a permission-check bypass in Windows PowerShell 5.1 sessions; fixed Bash permission checks mishandling very long commands (over 10,000 chars), zsh variable subscripts, and certain help/man commands.
- New Features: Introduced the EndConversation tool, allowing Claude to terminate highly abusive or jailbreak-attempt sessions (consistent with claude.ai); added a periodic progress heartbeat for long-running tool calls; added permission prompts for Docker commands with daemon-redirect flags.
- Observability: Added message-level UUID and tool source attributes to OpenTelemetry log events, with configurable content truncation limits.
More from coding & agent
- A 9B Ollama agent can run a fully local DJ radio with tools, memory, and TTS — pinku1 · 2026-07-27
- Bugbot rejects an MCP permission flag because it would break path-scoped isolation — zeeg · 2026-07-27
- One GPT-5.6 agent is guarding a Blink security system while another makes a parody rap album — repligate · 2026-07-27
- An agent got unblocked by reusing a logged-in browser, not stealth tricks — armanidev_ · 2026-07-27
- Paper argues graph topology can become the core operating system for AI agents — theomitsa · 2026-07-27
- Claude Code desktop adds UI markup feedback for smoother visual editing — EricBuess · 2026-07-27