Anthropic
Claude Code fixes deny rules that missed commands in the sandbox
Claude Code 2.1.289 fixes Bash deny and ask rules that missed a command behind a variable prefix in sandbox auto-allow, and Read deny rules missed via symlink.

Anthropic has fixed two shell patterns that let a command slip past a Claude Code Bash deny or ask rule when the sandbox auto-allows commands. One put an environment variable prefix with an expanded value ahead of the command. The other put a bare variable assignment there.
The fixes are in Claude Code 2.1.289, according to the entry dated Oct. 3, 2026 on the Claude Code changelog at code.claude.com. The npm registry lists the release as published Oct. 3 at 20:12 UTC, after 2.1.288 on Oct. 2.
Variable prefixes hid the command from the rules
The first entry says Bash deny and ask rules missed a command behind an environment variable prefix with an expanded value, such as TZ="$HOME" rm -rf build, when the sandbox auto-allows commands. The second says a Bash deny or ask rule was skipped under sandbox auto-allow when a bare variable assignment came before the command.
Read rules and plugins got fixes too
The changelog says Read deny rules did not apply to files @-mentioned, changed or selected in the IDE through a symlink. A deny or ask rule on a nested part of a compound shell command did not hold over a user-installed mod’s approval on managed machines, the entry says.
Another entry fixes a user-installed plugin being able to rewrite the descriptions of an organization-managed MCP server’s sign-in tools.
The rest of the release is mostly fixes
Claude Code 2.1.289 adds agent.spawn for teammates, one agent id across plugin hook events, and idle and waiting states in $.agent.list(). Most of the remaining entries fix plugin and mod rendering.
Published artifact pages could freeze or crash the reader’s browser tab on short code blocks with many unclosed <script> tags, according to the changelog. A matching fix covers the terminal freezing on such code blocks. Installed mods now load in the first session after an upgrade.
In the VSCode extension, the release reverts a 2.1.288 change to claude auth status that may have made sign-outs more frequent.
The previous release, 2.1.288, fixed a dangerous rm inside bash -c and sh -c running without a prompt, according to the changelog entry dated Oct. 2, 2026. The Lab Notes covered it Oct. 3.
Analysis
We think anyone who relies on deny rules to protect files or commands should update to 2.1.289. Two permission-rule fixes in a row, 2.1.288 and now this one, mean the rules had more than one gap.
A deny rule is a setting from a user or an administrator that blocks a command or a file read. An ask rule forces a prompt first. Sandbox auto-allow lets commands run without a prompt when they stay inside the sandbox. In that mode the rule is the check meant to stop a dangerous command. We read the two Bash entries as cases where the rule failed to catch a command it should have caught.
A symlink is a file that points to another file. The changelog says Read deny rules now apply to files reached through one when they are @-mentioned, changed or selected in the IDE.
