What happened
GitHub advisory (GHSA-gfvf-j8jh-jxxw) confirms the policy-fetch preference bug; MDM/file-based managed settings were unaffected. Fix in 2.1.260. Requires local access to a device with a stored key — an enterprise-governance bypass rather than a direct RCE.
Why it matters
Coding-agent governance/deny rules are a core control for enterprise AI use; this silently disables them for a session that still consumes the org account, letting an attacker or unwitting user bypass permission deny-lists and model restrictions enforced by managed policy.
Attack vector
When a device holds a stored Claude Code API key (e.g. from an earlier /login) and the user signs in with Enterprise/Team, the client prefers the stored key when fetching server-managed settings; if the settings endpoint rejects it, the session runs without org policy or with a stale cached copy while still acting as the org account.
Affected systems
Claude Code: Enterprise 2.0.68+, Team 2.1.38+; fixed in 2.1.260 (auto-update already delivered)
Mitigation
Update Claude Code to 2.1.260 or later (standard auto-update already applied).