Claude Code v2.1.223 Patches Multiple Permission Bypass and Sandbox Escape Flaws

ashwin-ant · ghdev · 2026-08-06

Anthropic has released Claude Code v2.1.223, focusing heavily on security and permission hardening. Key fixes include patching a Bash permission bypass where crafted commands could hide from checks, blocking dynamic import() in workflow scripts from running code outside the sandbox, and closing a gap where an agent's bypassPermissions mode ignored organizational disable policies.

The update also introduces a warning for restricted subagent model fallbacks, improves model discovery for Vertex AI and Bedrock gateways, and adds a /teleport hint for seamlessly transitioning cloud sessions to local environments.

Original post →

More from coding & agent

coding & agent channel →