Claude Code Closes Permission and Read-Block Bypasses

Claude CodeView original changelog

Claude Code 2.1.290 patches a batch of cases where deny rules, read blocks and auto-approval could be sidestepped. Affected paths include variable-prefixed declare and export commands, pasted image paths, rg and git grep wildcards, zsh variable parsing, and symlinks swapped mid-read. It also stops project settings from enabling Claude in Chrome and asks before running pyright or some ps forms.

Key Takeaways

  • Deny and ask rules now catch commands whose names come from variables set as a prefix on declare, typeset, export or readonly.
  • Read deny rules now cover pasted or dragged image paths and file names listed for an @-mentioned folder.
  • Symlink swaps mid-read could return files outside the approved set on image reads and @-mentions, and are now closed.
  • Wildcard-expanding read-only commands such as rg and git grep, and zsh-specific variable names, now prompt instead of auto-approving.
  • Project settings can no longer enable Claude in Chrome, so a cloned repository cannot switch the browser integration on by itself.
  • pyright and more ps forms now ask for permission instead of being treated as read-only.

Deny and ask rules that were missed

Claude Code 2.1.290 fixes several cases where a rule the user configured did not fire. A deny or ask rule could miss a command or path whose name came from a variable set as a prefix on declare, typeset, export or readonly. Read deny rules did not apply to image paths pasted or dragged into the prompt, or to file names listed for an @-mentioned folder. Bash permission checks also skipped Read deny rules and the outside-directory read block for a wildcard in some option values of read-only commands. Separately, some permission rules and safety checks were not applied to a tool call after a PreToolUse hook rewrote its input. All of these now apply.

Commands that were auto-approved too easily

Bash permission checks no longer auto-approve some read-only commands, such as rg or git grep, whose arguments the shell would still expand as wildcards. Certain commands whose variable names zsh reads differently from bash now prompt for approval. A short form of a git clone option no longer keeps the sandbox exemption from a pattern like git * in sandbox.excludedCommands. Sandboxed Monitor tool commands no longer skip the prompt under sandbox auto-allow, and plan mode no longer lets the auto mode classifier approve non-read-only connector tools that carry a server-pushed ask policy.

Reads that escaped the approved set

An image read on macOS and Windows could return a file outside what was approved through a link swapped mid-read. An @-mention under the read block or --restricted had the same weakness. A project CLAUDE.md, rule or AGENTS.md symlinked outside the working directories could load despite permissions.blockReadsOutsideWorkingDirectories or a Read deny rule. URL patterns with a wildcard inside an xn-- host label also matched inconsistently between processes. Both are fixed.

Policy and settings boundaries

The disableClaudeAiConnectors and allowedMcpServers URL rules now apply to MCP entries declared in .mcp.json, plugins or agents that previously slipped through. A user-installed mod can no longer cause an organization's plugin to be unloaded or an organization's guard to skip its check; the mod is unloaded instead. Background workers no longer honor --allow-dangerously-skip-permissions on respawn unless the bypass disclaimer was accepted, and --restricted sessions no longer open the cross-session messaging socket. The --channels permission relay now ignores a reply ID that repeats within a session.

Behavior changes

A project's settings files can no longer turn on Claude in Chrome. Use --chrome, /chrome or user settings instead. A repository's .claude/settings.json can no longer set CLAUDE_CODE_DISABLE_ATTACHMENTS. The Bash tool now asks before running pyright, and more forms of ps ask for approval. Skills and custom commands refuse a ! shell command containing raw control characters.