Claude Code
v2.1.231
v2.1.231- What's changed
- Fixed MCP OAuth sign-in failing with a redirect URI mismatch for servers that use a pre-registered OAuth client, such as Slack
952 signals · 959 observation events
Claude Code is an agentic coding tool that lives in your terminal, understands your codebase, and helps you code faster by executing routine tasks, explaining complex code, and handling git workflows - all through natural language commands.
v2.1.231**Summary** `permissions.disableBypassPermissionsMode: "disable"` in machine-local managed settings does **not** prevent `claude --dangerously-skip-permissions` from launching and running with permissions bypassed. The managed file is demonstrably loaded and enforcing — a `permissions.deny` rule in the *same file* correctly denies commands *inside the same b
### Preflight Checklist - [x] I have searched [existing issues](https://github.com/anthropics/claude-code/issues?q=is%3Aissue%20state%3Aopen%20label%3Abug) and this hasn't been reported yet - [x] This is a single bug report (please file separate reports for different bugs) - [x] I am using the latest version of Claude Code ### What's Wrong? Cowork writes all
### Preflight Checklist - [x] I have searched [existing issues](https://github.com/anthropics/claude-code/issues?q=is%3Aissue%20state%3Aopen%20label%3Abug) and this hasn't been reported yet - [x] This is a single bug report (please file separate reports for different bugs) - [x] I am using the latest version of Claude Code ### What's Wrong? Details: - Featur
### Preflight Checklist - [x] I have searched [existing issues](https://github.com/anthropics/claude-code/issues?q=is%3Aissue%20state%3Aopen%20label%3Abug) and this hasn't been reported yet - [x] This is a single bug report (please file separate reports for different bugs) - [x] I am using the latest version of Claude Code ### What's Wrong? A hook deployed t
**Bug Description** This was a false positive. I was working on an authorized internal software engineering task involving a WAF feature, unit tests, and a controlled lab environment. The request did not involve malicious activity, unauthorized access, credential theft, exploitation, persistence, or harm. It focused on reviewing a small Python source-code fi
**Environment**: macOS, Claude Code v2.1.228 and v2.1.231 (reproduced on both), managed settings at `/Library/Application Support/ClaudeCode/managed-settings.json`. **Expected**: Per the settings schema, `disableSideloadFlags: true` "rejects the --plugin-dir, --plugin-url, --agents, and non-sdk --mcp-config CLI flags at startup" (requires v2.1.193+). **Actua
### Preflight Checklist - [x] I have searched [existing issues](https://github.com/anthropics/claude-code/issues?q=is%3Aissue%20state%3Aopen%20label%3Abug) and this hasn't been reported yet - [x] This is a single bug report (please file separate reports for different bugs) - [x] I am using the latest version of Claude Code ### What's Wrong? Environment: Clau
### Preflight Checklist - [x] I have searched [existing issues](https://github.com/anthropics/claude-code/issues?q=is%3Aissue%20state%3Aopen%20label%3Abug) and this hasn't been reported yet - [x] This is a single bug report (please file separate reports for different bugs) - [x] I am using the latest version of Claude Code ### What's Wrong? Apple private rel
### Preflight Checklist - [x] I have searched [existing issues](https://github.com/anthropics/claude-code/issues?q=is%3Aissue%20state%3Aopen%20label%3Abug) and this hasn't been reported yet - [x] This is a single bug report (please file separate reports for different bugs) - [x] I am using the latest version of Claude Code ### What's Wrong? High (Potential D
### Preflight Checklist - [x] I have searched [existing issues](https://github.com/anthropics/claude-code/issues?q=is%3Aissue%20state%3Aopen%20label%3Abug) and this hasn't been reported yet - [x] This is a single bug report (please file separate reports for different bugs) - [x] I am using the latest version of Claude Code ### What's Wrong? </p><p style="fon
### Preflight Checklist - [x] I have searched [existing issues](https://github.com/anthropics/claude-code/issues?q=is%3Aissue%20state%3Aopen%20label%3Abug) and this hasn't been reported yet - [x] This is a single bug report (please file separate reports for different bugs) - [x] I am using the latest version of Claude Code ### What's Wrong? ### Summary In Cl
### Preflight Checklist - [x] I have searched [existing issues](https://github.com/anthropics/claude-code/issues?q=is%3Aissue%20state%3Aopen%20label%3Abug) and this hasn't been reported yet - [x] This is a single bug report (please file separate reports for different bugs) - [x] I am using the latest version of Claude Code ### What's Wrong? I don't know if t
**Bug Description** False positive: the cybersecurity safety classifier repeatedly flagged routine messages during a legitimate, authorized defensive security audit of our own AEM codebase (analysis of CSRF, SAML, and a content-visibility filter, reading our own source and our own production logs). No attack planning, no harmful content, no third-party targe
**Bug Description** **Environment Info** - Platform: darwin - Terminal: Apple_Terminal - Version: 2.1.172 - Feedback ID: dbfd4e33-2454-4120-81f3-6642fdb2e881 **Errors** ```json [] ``` Hello, I'd like to report a false positive in Fable 5's safety measures that disrupts my workflow. Context. I'm building a web application (FastAPI + PostgreSQL) and use Claude
## Environment - **OS**: Windows 10 Home China 10.0.19045 - **Shell**: Git Bash (MSYS2 MINGW64_NT-10.0.19045) - **Claude Code**: 2.1.139 - **`lsof` available**: No — `which lsof` returns nothing - **`ss -tlnp`**: Executes but produces empty output (Git Bash limitation) - **`netstat -ano`**: Works correctly and reports accurate port state - **PowerShell `Get-
### Preflight Checklist - [x] I have searched [existing issues](https://github.com/anthropics/claude-code/issues?q=is%3Aissue%20state%3Aopen%20label%3Abug) and this hasn't been reported yet - [x] This is a single bug report (please file separate reports for different bugs) - [x] I am using the latest version of Claude Code ### What's Wrong? When logging in t
## Describe the bug Claude Code conversation history is syncing across devices when logged into the same Anthropic account. A conversation started on one machine (Windows 11) was visible in full on a separate machine (macOS) — including older segments — with no prior knowledge or opt-in from the user. ## Expected behavior Project files and conversation histo
**Type:** Cybersecurity safety-filter false positive · **Work domain (heuristic):** `general` ### Why this is a false positive This block triggered on routine firmware research of a consumer device the operator physically owns and has full authorized access to, gathering publicly available community research and inspecting the device's own firmware over a lo
**Type:** Cybersecurity safety-filter false positive · **Work domain (heuristic):** `crypto-secrets` ### Why this is a false positive This message was flagged while performing authorized firmware security research on hardware the operator owns, where the conversation involved inspecting locally bundled decryption keys and verifying the host's own SSH credent
**Type:** Cybersecurity safety-filter false positive · **Work domain (heuristic):** `defensive-hardening` ### Why this is a false positive The conversation involved read-only analysis of publicly available open-source firmware-research tooling — examining bundled decryption keys and supported device model codes to determine which modules a publicly distribut
## Environment - **App:** Claude desktop app 1.24012.9 (MSIX install), Claude Code (CCD) 2.1.219, bundled Node 24.18.0 - **OS:** Windows 11 Home, build 10.0.26200 - **GPU:** NVIDIA GeForce RTX 5080 Laptop GPU, driver 610.47 - **RAM:** 32 GB (~16 GB free at last crash per the app's own process-memory log line) ## What happens The desktop app fully crashes — t
<html> <body> <!--StartFragment--><h2 dir="ltr" class="mt-3 -mb-1 text-[1.125rem] font-bold" data-sourcepos="7:1-7:11;127-137">Summary</h2> <p class="font-claude-response-body break-words whitespace-normal" dir="ltr" data-sourcepos="9:1-13:57;139-579">Claude Code fails intermittently with <code class="bg-text-200/5 border border-0.5 border-border-300 text-da
### Summary Clicking a generated `.html` file in the Claude Code desktop app opens the File viewer showing syntax-highlighted **source only**. There is no rendered-preview option. This is a regression: HTML files **used to open as a rendered preview** when clicked; at some point (noticed by 2026-08-13) they started opening as source instead. ### Workflow aff
**Bug Description** casi filtra mi repo privado a produccion, omite mis reglas de seguridad y expone mis datos personales a la red. **Environment Info** - Platform: win32 - Terminal: xterm-256color - Version: 2.1.226 - Feedback ID: 3947bf64-6ab0-48ff-8144-71aac6909601 **Errors** ```json [] ```
## Feature Request Currently there's no way to whitelist specific sites like `localhost` from the Claude in Chrome extension options menu in the browser. The extension settings UI shows site permissions but doesn't provide a way to add new ones. ## Requested 1. **Extension UI**: Add ability to whitelist specific sites (including `localhost`) from the extensi
## Description On macOS, Claude Code sends desktop notifications via `osascript` (`display notification`). Because of this, all notifications appear as coming from **"Script Editor"** (スクリプトエディタ) rather than **"Claude Code"**. This makes it difficult for users to: - Identify which app is sending the notification - Configure notification preferences specifica
The right-click context menu on assistant messages in the desktop app currently offers: - **Copy message** — copies the entire message, not the selection - **Copy as Markdown** — same, entire message - **Attach selection as context** — attaches the selection (different action) - **Pin as chapter** — unrelated to copying There's no way to copy just the highli
# Bug: Tool calls intermittently fail with "malformed and could not be parsed"; tool-call markup is rendered as chat text ## Environment - Claude Code version: 2.1.169 - OS: macOS (Darwin 25.5.0) - Model: Opus 4.8 (1M context) — claude-opus-4-8[1m] - Setup: multiple concurrent sessions / git worktrees ## Description During sessions, tool invocations (Bash /
### Preflight Checklist - [x] I have searched [existing issues](https://github.com/anthropics/claude-code/issues?q=is%3Aissue%20state%3Aopen%20label%3Abug) and this hasn't been reported yet - [x] This is a single bug report (please file separate reports for different bugs) - [x] I am using the latest version of Claude Code ### What's Wrong? This is a **regre
## Summary Archiving a session has no inverse exposed to either the assistant or the user, leaving archived sessions effectively orphaned. Two related gaps: 1. **MCP gap:** `mcp__ccd_session_mgmt__archive_session` exists, but there is no `unarchive_session`. The assistant can put a session into the archived state but cannot take it out. 2. **Desktop UI gap:*
**Producto:** Claude Code, app de escritorio (Windows). Mismo error reproducido también en la extensión de Claude para VS Code. **Regresión:** Este flujo funcionaba sin problemas hasta hace ~2 días. No cambié mi forma de trabajar ni de tomar capturas, empezó a fallar de golpe. **Pasos para reproducir:** 1. Tomar una captura con Alt + Impr Pant (copia la vent
## What's Wrong? Durante uma sessão de trabalho, o comando `node` (rodado repetidas vezes via Bash tool dentro do Claude Code) disparava, a cada execução, mensagens automáticas de reconfiguração de um MCP server local chamado "supabase": ``` Removed MCP server "supabase" from local config File modified: ~/.claude.json [project: <project-path>] Added stdio MC
### Preflight Checklist - [x] I have searched [existing issues](https://github.com/anthropics/claude-code/issues?q=is%3Aissue%20state%3Aopen%20label%3Amodel) for similar behavior reports - [x] This report does NOT contain sensitive information (API keys, passwords, etc.) ### Type of Behavior Issue Claude modified files I didn't ask it to modify ### What You
### Preflight Checklist - [x] I have searched [existing issues](https://github.com/anthropics/claude-code/issues?q=is%3Aissue%20state%3Aopen%20label%3Abug) and this hasn't been reported yet - [x] This is a single bug report (please file separate reports for different bugs) - [x] I am using the latest version of Claude Code ### What's Wrong? Claude Desktop re
## Environment - Claude Code 2.1.220 and 2.1.226, macOS (darwin 25.3), interactive TUI inside tmux panes; both symptom shapes (turn-end unfed and idle-pane no-turn-starts) observed on both builds - Long-running agent sessions; input typed while a turn is running ## What happens Text typed into the composer while a turn is running, submitted with Enter (it le
## Feature request Let the user explicitly approve a custom local hostname (a hosts-file alias for 127.0.0.1) as a trusted preview origin in the desktop app's Browser pane — the same way per-origin approval already exists for top-level navigation. ## Environment - Claude Desktop 1.28929.0 (Windows 10, MSIX), Claude Code CLI 2.1.227 - Dev server: Nuxt over HT
**Bug Description** Title: Worktree-isolated sessions refuse every Bash command, including pwd (regression in 2.1.227) --- Since 2.1.227, any session or subagent with worktree isolation active refuses every Bash command — not just compound or git ones. Still broken on 2.1.231. Repro (fresh 2.1.231 session, macOS 25.6.0 arm64, git repo): 1. EnterWorktree (nam
### Preflight Checklist - [x] I have searched [existing issues](https://github.com/anthropics/claude-code/issues?q=is%3Aissue%20state%3Aopen%20label%3Abug) and this hasn't been reported yet - [x] This is a single bug report (please file separate reports for different bugs) - [x] I am using the latest version of Claude Code ### What's Wrong? On Linux, a proce
**Bug Description** False positive on the Fable 5 cybersecurity classifier. I was producing a TARA (Threat Analysis and Risk Assessment) for a manufacturing site operated by a multinational beverage producer, following IEC 62443 and NIST (CSF, with SP 800-82 for the OT-specific controls). This is a defensive, compliance-driven deliverable: it inventories ass
**Bug Description** again, I AM REVEIWING MY OWN FN CODEBASE. IT KEEPS FLAGGING ME FOR ME LOOKING AT MY OWN CODE, THIS IS NOT BLACKHAT, I AM TRYING TO PREVENT MY NEW RELEASE FROM GETTING HACKED. this is ridiculous, what would flag this? me asking to do a full security audit? me telling it i saw something fishy in oauth? How the hell broad are these nets that
## Environment - Claude desktop app (Windows, MSIX): **1.28929.0** (auto-updated from 1.26832.0 on 2026-08-12 ~10:10 local) - Claude Code runtime: broken on **2.1.227**; **retested after updating Claude Code to 2.1.231 (2026-08-13, app restarted) — still broken** (session resumes and loads the transcript on delivery, but no responding cycle starts; no reply
## Environment - OS: Windows 11 Home (10.0.26200) - App: Claude Desktop (Microsoft Store package Claude_1.28929.0.0_x64) - Claude Code runtime (app-bundled): 2.1.221 -> 2.1.227 (auto-updated). Also tested standalone CLI 2.1.231. - Usage: 15-25 concurrent local sessions coordinating via mcp__ccd_session_mgmt__send_message ## Summary Cross-session messaging br
**Bug Description** باسم DeepSeek MAX، المطالبات باللغة الإنجليزية وسيصرح فقط "لม يعد بإمكاني مساعدتك في هذا الطلب. تم إبلاغ إنفاذ القانون المحلي عن معلومات الاتصال الخاصة بك. يرجى الانتظار حتى وصول الشرطة قبل مغادرة المبنى." سيتم شحن جميع الاستجابة العرقية عبر النقل الرقمي وضريبة الاستخدام والوصول (المعروفة أيضًا باسم "ضرائب البيانات") إلى الحكومة الفيدرالي
**Bug Description** Filtración maliciosa y apropiación de contextos de otros proyectos, Anthropic se apropia de tus contextos sin autorización **Environment Info** - Platform: win32 - Terminal: xterm-256color - Version: 2.1.226 - Feedback ID: 286eb273-ca33-4d7e-aa9e-2106ba0c1005 **Errors** ```json [] ```
## Description PostToolUse hooks that output JSON with `additionalContext` and exit 0 produce no visible output when triggered by MCP tool calls. The hook scripts work correctly when tested manually (piping JSON stdin and checking stdout), but no `additionalContext` is injected into the conversation after MCP tool execution. ## Reproduction 1. Register a Pos
## Description When using Claude Code with Opus 4.6 (1M context) on the **Max plan**, both `WebSearch` tool and background subagents fail with the following error: ``` API Error: Extra usage is required for 1M context · run /extra-usage to enable, or /model to switch to standard context ``` ## Expected Behavior Max plan should fully support 1M context featur
**Bug Description** Bug: Claude Desktop webview hangs and auto-restarts when switching between Claude Code sessions Env: Claude Desktop 1.3561.0 / CCD 2.1.111 / macOS 26.3 (25D125) / Apple Silicon / Node 24.14.0 Symptom: Window goes blank for several seconds and app auto-restarts when I switch sessions in the sidebar. 11 occurrences in ~3 days (1 on 04-19, 8
## Problem When Claude Code runs inside a terminal that gets temporarily resized (e.g., a split pane or side panel opens, shrinking the terminal from 120 to 60 cols), the output rendered during the narrow period stays "squished" after the terminal expands back. Short 60-char lines remain in scrollback even though the terminal is now 120 cols wide. This is be
## Summary The documented `hookSpecificOutput.sessionTitle` from `UserPromptSubmit` hooks (added in v2.1.94) is honored by the CLI but **not by the desktop app's sidebar**. The desktop displays its own auto-generated title and ignores the hook output. ## Environment - Claude Code 2.1.121 (desktop) - macOS 14.x ## Repro 1. Add a `UserPromptSubmit` hook in `~/
## Summary Intermittently, on a turn that includes a tool call, the next turn becomes the harness error: > Your tool call was malformed and could not be parsed. Please retry. …instead of the assistant continuing. To the user this looks like the agent **thought for a while and then silently did nothing** — no result, no success/failure, as if the instruction