Claude Code Closes rm, BASHPID and Fail-Open Hook Gaps in Permission Checks

Claude CodeView original changelog

Claude Code 2.1.288 patches four gaps where the agent could act outside what the user authorized. A dangerous rm inside a bash -c script could run unprompted in bypassPermissions mode or under a shell allow rule, a BASHPID arithmetic assignment slipped past the prompt, hooks that failed to match were skipped, and sandbox credential file entries on git config files were ignored under one setting. Updating closes all four.

Key Takeaways

  • A dangerous rm inside bash -c or sh -c no longer runs unprompted in bypassPermissions mode or under a shell allow rule.
  • BASHPID assignments evaluated as arithmetic now trigger a permission prompt instead of passing silently.
  • Broken PreToolUse and PermissionRequest hooks now block the call, so policy checks fail closed rather than being skipped.
  • sandbox.credentials.files entries on git config files now work even with blockReadsOutsideWorkingDirectories enabled.
  • The fixes continue a week-long run of permission hardening, following the 2.1.287 rm redirect safeguard.
  • Anyone using bypassPermissions or broad allow rules gains the most from updating to 2.1.288.

Four trust-boundary fixes in one release

Claude Code 2.1.288 includes four fixes that all concern the same question: could the agent do something the user had not authorized? Each one is now closed.

Dangerous rm hidden in bash -c

A dangerous rm, such as one targeting / or the home directory, could run without a prompt when it was wrapped inside a bash -c or sh -c script. This applied in bypassPermissions mode and under a shell allow rule. Claude Code 2.1.288 now recognizes the destructive command inside the wrapped script and asks first. This follows a fix in 2.1.287 that restored the always-ask safeguard for rm when the same command also redirected output to a ~ or wildcard path.

BASHPID arithmetic assignment

The Bash permission check now prompts before a BASHPID assignment whose value the shell would evaluate as arithmetic. Previously such an assignment was allowed silently, even though evaluating arithmetic can execute embedded expressions.

Hooks that fail now block instead of skipping

PreToolUse and PermissionRequest hooks were skipped when matching them failed or when the tool's input could not be serialized to JSON. That meant a policy hook could quietly not run. In 2.1.288 the call is blocked instead, so a broken hook fails closed rather than open.

Sandbox credential files on git config

Entries under sandbox.credentials.files that pointed at git config files did not take effect while permissions.blockReadsOutsideWorkingDirectories was turned on. They now apply as configured, so the intended credential protection holds.

What to do

All four fixes ship in 2.1.288. Teams that rely on bypassPermissions, shell allow rules, policy hooks or sandbox credential protection should update promptly.

Claude Code Closes rm, BASHPID and Hook Permission Gaps | Yet Another Changelog