What happened
Anthropic shipped Claude Code 2.1.289 on 2026-10-03 (in-window), fixing at least five security-relevant gaps: Bash deny/ask rules missing commands behind environment-variable prefixes and bare assignments under sandbox auto-allow, Read deny rules bypassed for files accessed via symlinks in the IDE, deny/ask rules on nested compound commands not holding over a user-installed mod's approval on managed machines, and a user-installed plugin being able to rewrite the descriptions of an org-managed MCP server's sign-in tools. Two prior releases (2.1.287/2.1.288) closed related rm / credential-file rule bypasses, showing a recurring pattern of text-pattern matchers being beaten by shell semantics.
Why it matters
Coding agents execute commands with the developer's privileges and read MCP tool descriptions to decide what a tool does. A Bash deny/ask bypass turns an evilly-crafted prompt or malicious file into an unapproved destructive or credential-stealing command; a plugin rewriting an org-managed MCP server's tool descriptions is a prompt-injection channel into a trusted tool. This is the first-party fix for the active agent-permission rule gap debated over the past week - defenders should deploy it and stop treating deny rules as a hard boundary.
Attack vector
The changelog details text-matching rule gaps: a Bash deny/ask rule could be missed behind an environment-variable prefix whose value expands (e.g. TZ="$HOME" rm -rf build) and behind a bare variable assignment, both under sandbox auto-allow; Read deny rules were bypassed for IDE symlinked files; and a user-installed plugin could rewrite the descriptions of an organization-managed MCP server's sign-in tools, feeding the model misleading instructions about a trusted tool.
Affected systems
Anthropic Claude Code before 2.1.289 (released 2026-10-03)
Mitigation
Upgrade to Claude Code 2.1.289 (published 2026-10-03). Administrators should push the release on managed machines first, since the managed-machine and plugin-description fixes affect org policy. Do not rely on deny/ask rules as the security boundary - the sandbox, filesystem permissions, and backups are the backstop.