2026-08-14 · Anthropic

v2.1.233

securitymodels

read at source ↗ github.com

v2.1.233

Source: Anthropic Claude Code Date: 2026-08-14 URL: https://github.com/anthropics/claude-code/releases/tag/v2.1.233

Summary

A maintenance release that buries one real security fix among routine polish: Windows paths spelled with the NT \??\ device prefix were bypassing UNC path validation, closing an NTLM credential-leak vector. Alongside it: opt-in memory cgroup limits for Bash tool commands on Linux, a skill/command argument-substitution fix preventing re-expansion as template markers, GitLab merge-request support in --worktree, and task-tracking tools (TaskCreate/TodoWrite) quietly disabled by default on the newest model tier (Opus 4.8, Sonnet 5, Fable 5, Mythos 5).

Implications

  • The effect-guard thread. The credential-leak fix and the Bash memory-cgroup addition are both self-imposed limits on what the harness’s own tools can do unsupervised — the same shape as the schema-migration gate beads shipped days earlier, just diffused into a changelog line instead of headlined.
  • Enforcement-is-leaky thread. A path-validation bug closing an NTLM leak vector is exactly the kind of boundary-enforcement defect that matters more than any feature line in the same release — worth tracking whether it gets a CVE or stays a silent patch.
  • Watch: whether disabling TodoWrite/TaskCreate by default on newer models signals a broader shift away from harness-managed task state toward model-native planning.

← all signals