Agent Frameworks & Harnesses 2026-10-06

Framework Watch: Claude Code 2.1.290 Closes Symlink and Deny-Rule Gaps; LangGraph 1.2.13 Fixes Time-Travel Forks and Stale Interrupts

Claude Code 2.1.290, released late on October 5 (UTC), fixes a batch of permission and file-access gaps -- symlinks swapped mid-read, deny rules missed behind shell prefixes, wildcard expansion in 'read-only' commands -- and adds org-level approval ceilings for plugin hooks. LangGraph 1.2.13, the same day, fixes checkpoint forking and stops reporting interrupts that were already answered.

Two agent frameworks shipped on October 5, 2026: Anthropic's Claude Code 2.1.290 (published 23:33 UTC) and LangChain's LangGraph 1.2.13.

Claude Code 2.1.290: what operators should act on

  • File-access gaps. An image read on macOS and Windows, or an @-mention under the read block or --restricted, could return a file outside what was approved via a link swapped mid-read; both are fixed. A project CLAUDE.md, rule or AGENTS.md symlinked outside the working directories no longer loads under blockReadsOutsideWorkingDirectories or a Read deny rule, and Read deny rules now apply to pasted or dragged image paths.
  • Command-matching gaps. Deny and ask rules missed a command or path whose name came from a variable set as a prefix on declare, typeset, export or readonly. Some read-only commands such as rg or git grep were auto-approved even when the shell would expand wildcards in their arguments; they now prompt.
  • Policy enforcement. disableClaudeAiConnectors and allowedMcpServers URL rules now apply to MCP entries declared in .mcp.json, plugins or agents. Plan mode no longer lets the auto-mode classifier approve non-read-only connector tools that carry a server-pushed ask policy. A user-installed mod can no longer make an organization's guard skip its check or get an organization's plugin unloaded.
  • Admin visibility. New warnings when a managed settings file is a link to a file outside the managed folder, and when managed settings ignore user-configured sandbox read paths or domains. Plugin hooks gain an agentId on tool.check to tell subagent checks from the main session's, and a ceiling naming the approval an organization requires for a tool.
  • Reliability. WebFetch no longer silently drops page text past 100,000 characters; it reports how much was unread and takes an offset. Scheduled tasks now survive compaction on resume, and a --channels reply ID that repeats within a session can no longer approve a different prompt.

LangGraph 1.2.13: checkpoints and interrupts

The release is all fixes, concentrated on state history: LangGraph now forks before replaying an update checkpoint the thread has moved past, keeps an update_state on an older checkpoint out of other branches, avoids replaying an abandoned branch into a delta-channel fork, and hydrates subgraph delta channels with the caller's saver. The human-in-the-loop fix is the one to note: get_state no longer reports interrupts that have already been answered, which could leave an approval UI showing a request as still pending.

Who should act. Claude Code administrators relying on Read deny rules, blockReadsOutsideWorkingDirectories or MCP allowlists should update, since several of those controls could be sidestepped. LangGraph users who use time travel or update_state on past checkpoints, or who drive approval UIs from get_state, should upgrade and re-test branch behaviour.

Analysis: the Claude Code list continues a run of releases whose security fixes are about edges -- symlinks, shell prefixes, wildcard expansion, config declared in an unexpected file -- rather than headline features. That is what mature permission systems look like: the policy model is settled, and the work is making every path honour it.

Claude Code 2.1.290 (October 5) closes file-access and deny-rule gaps around symlinks, shell prefixes, wildcard expansion and MCP allowlists and gives organizations approval ceilings for plugin hooks, while LangGraph 1.2.13 fixes checkpoint forking and stops reporting already-answered interrupts -- both updates for anyone relying on those controls.