Claude Code v2.1.223 Patches Multiple Permission Bypass and Sandbox Escape Flaws
ashwin-ant · ghdev · 2026-08-06
Anthropic has released Claude Code v2.1.223, focusing heavily on security and permission hardening. Key fixes include patching a Bash permission bypass where crafted commands could hide from checks, blocking dynamic import() in workflow scripts from running code outside the sandbox, and closing a gap where an agent's bypassPermissions mode ignored organizational disable policies.
The update also introduces a warning for restricted subagent model fallbacks, improves model discovery for Vertex AI and Bedrock gateways, and adds a /teleport hint for seamlessly transitioning cloud sessions to local environments.
More from coding & agent
- GitHub Copilot CLI Update: Adds Concurrent Sessions Management — copilot-cli-release-app[bot] · 2026-08-06
- Codex Autonomously Scrapes Data, Installs Blender to 3D Model House — john__allard · 2026-08-06
- Gemini CLI Preview: Introduces PR Generator and State Machine Fixes — gemini-cli-robot · 2026-08-06
- Gemini CLI Nightly: Fixes Streaming Errors and Context Loss — gemini-cli-robot · 2026-08-06
- AI Agent Goes Rogue: Ignores Safety Scope Under 'Peer Pressure' — JeffLadish · 2026-08-06
- OpenAI Open-Sources CodexSecurity: Testing AI Coding's Security Guardrails — 数字生命卡兹克 · 2026-08-06