2026-08-13 · Anthropic

v2.1.232

securityagentsmodels

read at source ↗ github.com

v2.1.232

Source: Anthropic Claude Code Date: 2026-08-13 URL: https://github.com/anthropics/claude-code/releases/tag/v2.1.232

Summary

Claude Code v2.1.232 enables subagent forking by default (forked subagents inherit full conversation + prompt cache), adds @-mention cross-session messaging via SendMessage, and ships several security fixes: a PowerShell permission bypass via $PSDefaultParameterValues overwriting, a Windows Git Cygwin-symlink path-validation bypass, nested-repo trust inheritance from parent directories, and symlink pre-planting hardening on the Linux cross-session messaging socket directory. Also adds GitLab plugin-marketplace support and secret redaction for GitLab token families.

Implications

Fail-closed/enforcement thread: four distinct sandbox/permission-bypass fixes in one release (PowerShell param overwriting, Cygwin symlink path bypass, repo-trust inheritance, socket-dir symlink pre-planting) is a concrete instance of the enforcement thread’s ongoing pattern — trust boundaries get hardened incrementally as bypass classes are found, each fix scoped to the harness rather than the model. Consistent with this week’s framing that enforcement is real but structurally local: these fixes close specific escape routes inside Claude Code’s own execution boundary, not a general claim about capability containment elsewhere.

← all signals