Claude Code 2.1.289 patches @-mention symlink bypass of file read deny rules
ClaudeCodeLog · x · 2026-10-04
Full changelog for Claude Code CLI 2.1.289, covering 27 changes.
- New: agent.spawn lets teammates spawn shared agents, agent IDs are unified across plugin hook events, and $.agent.list() gains idle/waiting states.
- Security: Read deny rules now apply to @-mentioned, changed, or IDE-selected files even via symlinks, closing a bypass; deny/ask rules on nested parts of compound shell commands now hold over user-installed mod approvals on managed machines.
- Also fixed: user plugins can no longer rewrite org-managed MCP server sign-in descriptions; terminal freezes on unclosed <script> tags; stale plugin listings from local marketplaces; symlink hot reload; mods not loading after upgrades.
Related event: Claude Code 2.1.289 Adds agent.spawn, Fixes Permission Bypass(3 posts)→
More from coding & agent
- Vercel hits $600M annualized revenue, up 148%, as coding agents drive half of new business — evilrabbit_ · 2026-10-04
- Hallmark: an open-source skill making Claude Code, Cursor and Codex UIs look less AI-generated — tom_doerr · 2026-10-04
- Stop fine-tuning to fix retrieval problems: Oracle technologist on where knowledge should live — AI Engineer · 2026-10-04
- KMP: recovering project decisions and evidence across Claude and Codex via MCP — Mountain-Raise-4556 · 2026-10-04
- (Lean)DOOM: DOOM fully rewritten in the Lean proof assistant, with formal proofs included — akbirthko · 2026-10-04
- Jin: a minimalist coding agent that swaps MCP/plugins for prompts and bash — aldapsiger · 2026-10-04