← In the News

Claude Code 2.1.288 and 2.1.289 fix deny and ask rules that were skipped under sandbox auto-allow

Claude Code changelog · Anthropic · Versions 2.1.288 (October 2, 2026) and 2.1.289 (October 3, 2026)

Machine-readable Download Markdown

The changelog lists several permission fixes. One says a "Bash deny or ask rule" was "skipped under sandbox auto-allow when a bare variable assignment came before the command." Another covers deny and ask rules "missing a command behind an environment variable prefix with an expanded value (e.g. TZ="$HOME" rm -rf build) when the sandbox auto-allows commands." A third says a deny or ask rule on a nested part of a compound shell command did not hold "over a user-installed mod's approval on managed machines."

Two more concern guardrails that failed open. A dangerous rm, such as one on / or the home directory, inside a bash -c or sh -c script ran "without a prompt in bypassPermissions mode or under a shell allow rule." And PreToolUse and PermissionRequest hooks were skipped "when matching them failed or the tool's input could not be serialized to JSON"; the call is now blocked. 2.1.289 also fixes Read deny rules not applying to files changed or selected in the IDE through a symlink.

The changelog describes these as fixes. It does not say whether any were exploited or how many installs were affected, and this item rests on the changelog text alone.

Why it matters: The affected paths are the ones people use to let an agent run without a human approving each command: sandbox auto-allow, allow rules, and bypassPermissions. If your setup depends on a deny rule or a hook to stop a destructive command, these entries describe command shapes where it did not apply, so upgrading is the first step. They are also a reason to keep a second limit under the rules, such as a sandbox or a scoped working directory.