2.1.149

Claude Code 2.1.149 - リリースノート

2026年5月22日
Claude Code

日本語サマリー

Claude Code 2.1.149 のリリースノートの要約です。

⚠️ セキュリティ修正・重要な変更

  • PowerShell権限バイパスの修正: cd.. や cd\、cd~ などの組み込み cd 関数がワークスペース外へのディレクトリ移動を検知されず、後続コマンドで許可されていない場所の読み取りが可能になっていた問題を修正。
  • 権限解析の脆弱性修正: cd / pushd / popd 実行後の PWD / OLDPWD / DIRSTACK 変数の古い追跡値をパーサーが信頼してしまう問題を解消。
  • Sandboxの書き込み許可リスト修正: Git worktree環境において、許可範囲が共有 .git ディレクトリ(および hooks/, config の拒否)のみではなく、メインリポジトリのルート全体を誤ってカバーしていた問題を修正。
  • PowerShellの許可ルール修正: PowerShell(dotnet.exe build *) のようなプレフィックス/ワイルドカード許可ルールが、ネイティブ実行可能ファイルやスクリプトを正しく事前承認していなかった問題を修正。

💡 主な機能追加・改善

  • /usage コマンドの強化: スキル、サブエージェント、プラグイン、および MCP サーバーごとのコストなど、カテゴリ別の内訳を表示するように改善。
  • Enterprise向け新設定: managed-mcp.json と併用して claude.ai のクラウド MCP コネクタを読み込むための allowAllClaudeAiMcps 管理設定を追加。
  • UI/UXの改善: /diff の詳細ビューでのキーボードスクロール対応、GFMタスクリスト(チェックボックス)のレンダリング対応、/feedback にコンテキスト圧縮前の会話履歴を含めるように改善。

🐛 その他のバグ修正

  • システムクラッシュの解消: Bashツール内の find コマンドが、大規模なディレクトリツリーで macOS のシステムファイル/vnodeテーブルを枯渇させホストをクラッシュさせる問題を修正。
  • 起動時のフリーズ修正: managed-settings の承認ダイアログで「受け入れる」を選択した後にターミナルがフリーズする問題を解消。
  • スラッシュコマンドの挙動修正: 変更がない作業ツリーで /ultraplan やリモートセッションを作成すると失敗するエラー、および Ctrl+O トランスクリプトビューが新しいメッセージを追尾しない問題を修正。

原文(Release Notes)

What's changed

  • /usage now shows a per-category breakdown of what's driving your limits usage — skills, subagents, plugins, and per-MCP-server cost
  • /diff detail view can now be scrolled with the keyboard (arrows, j/k, PgUp/PgDn, Space, Home/End)
  • Markdown output now renders GFM task list checkboxes (- [ ] todo / - [x] done) instead of plain bullets
  • Enterprise: added the allowAllClaudeAiMcps managed setting to load claude.ai cloud MCP connectors alongside managed-mcp.json
  • Fixed a PowerShell permission bypass: built-in cd functions (cd.., cd\, cd~, X:) changed the working directory undetected, letting a later command read outside the workspace
  • Fixed the sandbox write allowlist in git worktrees covering the entire main repository root instead of only the shared .git directory (with hooks/ and config denied)
  • Fixed PowerShell prefix/wildcard allow rules (e.g. PowerShell(dotnet.exe build *)) not pre-approving native executables and scripts
  • Fixed a permission-analysis gap where the parser trusted stale variable-tracking values for PWD/OLDPWD/DIRSTACK across cd/pushd/popd
  • Fixed find in the Bash tool exhausting the macOS system file/vnode table and crashing the host on large directory trees
  • Fixed the managed-settings approval dialog leaving the terminal frozen after accepting at startup
  • Fixed /ultraplan and remote session creation failing with "Could not capture uncommitted changes" when the working tree has no real changes
  • Fixed otelHeadersHelper failing silently when the script path contains spaces; helper failures are now reported in /doctor and the debug log
  • Fixed the thinking spinner staying amber across tool calls and onto fresh thinking bursts
  • Fixed collapsed Bash output reporting the wrong hidden-line count for outputs with many short lines
  • Fixed slash-command argument-hint clipping trailing typed characters when the hint overflows the input box
  • Fixed argument-hint and progressive arg suggestions not appearing after Tab-completing a skill whose frontmatter name: differs from its directory basename
  • Fixed the status bar showing the user's baseline /effort setting instead of the effort level applied by skill/agent effort: frontmatter
  • Fixed Ctrl+O transcript view freezing at the moment it was opened instead of tailing new messages
  • Fixed editing a recalled prompt-history entry losing the edit when navigating further up/down with arrow keys
  • Fixed /config exit summary reporting phantom changes to auto-compact and theme when toggling unrelated settings
  • Fixed /insights crashing when cached session-meta files are missing optional fields
  • Fixed malformed PowerShell and History tool calls with missing input being misclassified as reads in transcript collapsing
  • Fixed renaming a Remote Control session from claude.ai or the Claude mobile app not updating the local session name for claude --resume
  • Fixed a race where a just-submitted prompt could appear twice in the up-arrow history
  • Fixed tapping the "Jump to bottom" pill in fullscreen mode not dismissing it immediately
  • Improved /feedback reports to include the conversation that happened before context compaction, making issues from earlier in long sessions easier to triage