Anthropic released Claude Code 2.1.289 on October 3, 2026, the day after 2.1.288. Most of its roughly 28 changelog items fix plugins and "mods" -- crashes, stale panes, rows drawing over each other. Five are security-relevant and worth reading closely if your setup depends on deny or ask rules.
- Env-var prefixes under sandbox auto-allow. Bash deny and ask rules could miss a command hidden behind an environment-variable prefix with an expanded value -- the changelog's example is
TZ="$HOME" rm -rf build-- when the sandbox auto-allows commands. - Bare assignments. Separately, a Bash deny or ask rule could be skipped under sandbox auto-allow when a bare variable assignment came before the command.
- Symlinks from the IDE.
Readdeny rules did not apply to files that were @-mentioned, changed or selected in the IDE through a symlink. - Managed machines. A deny or ask rule on a nested part of a compound shell command did not hold over a user-installed mod's approval on managed machines.
- Org-managed MCP servers. A user-installed plugin could rewrite the descriptions of an organization-managed MCP server's sign-in tools. Tool descriptions are what the model reads to decide what a tool does, so this was a route for a local plugin to mislead the agent about a trusted server.
The one notable feature: plugin hooks gain agent.spawn for teammates, a single agent id across plugin hook events, and idle and waiting states in $.agent.list(), which makes it easier for a plugin to supervise multi-agent sessions. The VS Code extension also reverts a 2.1.288 change to claude auth status that may have caused more frequent sign-outs.
Who should act. Teams that allow broad shell use under sandbox auto-allow and rely on deny rules for things like rm should upgrade. So should administrators who let users install their own plugins or mods on machines where the organization manages MCP servers and permission policy.
Analysis: this is the second release in a row whose most important fix is a permission rule that did not fire -- 2.1.288 fixed an unprompted rm inside bash -c. The common thread is that a rule matches text, while a shell interprets it, and every gap between the two (prefixes, assignments, nesting, symlinks) is a bypass. Deny rules are still worth having, but the dependable backstop is the layer below them: a sandbox that limits what a command can reach whatever its spelling, plus a policy that keeps user-installed extensions away from organization-managed integrations.
Claude Code 2.1.289 fixes five cases where deny or ask rules could be bypassed -- env-var prefixes, bare assignments, symlinked IDE files, managed-machine compound commands and plugin-rewritten MCP tool descriptions -- reinforcing that text-matching rules need a sandbox behind them.