2.1.251
Claude Code 2.1.251 - リリースノート
2026年8月28日
Claude Code
日本語サマリー
Claude Code 2.1.251 リリースノート要約
⚠️ 重要なセキュリティ修正・破壊的変更
- シンボリックリンク回避による権限チェック迂回を修正: ワーキングディレクトリ内で symlink が差し替えられた際、Read/Write/Edit が許可外の場所にアクセス可能だった問題。Grep/Glob の
Read(...)deny ルール回避も修正 - プラグインコマンドのパストラバーサルを修正: プラグインディレクトリ外を指すパスを拒否するよう変更
- プロジェクト設定の権限昇格を修正: プロジェクト設定でベータトレーシングや生 API ボディログを有効化できた問題、および OTLP コレクターのバイパスを修正
- サンドボックス内 Bash 出力ファイルの作成・読み取り方法を変更: サンドボックス化されたコマンドがファイルをリダイレクト・置換できないように
ANTHROPIC_CUSTOM_HEADERSが認証情報やルーティング系ヘッダー(Authorization,Hostなど)を設定する場合、承認を必須に変更- プロジェクト設定の
envでCLAUDE_CONFIG_DIR,CLAUDE_CODE_TMPDIR,TMPDIR/TMP/TEMPを設定できなくなった破壊的変更(shell・user・managed settings で設定する必要あり)
新機能
PreModelSwitch/PostModelSwitchフックイベントを追加。モデル切り替えを block・confirm・annotate 可能に- フォアグラウンド subagent のツール呼び出しを Remote Control クライアントにライブストリーミング
/usageに Spend limit バー、rate_limits.spend_limitstatus line フィールドを追加/costにプロンプトキャッシュの行(ヒット率、misses、warm/cold)とprompt_cacheオブジェクトを追加
主な仕様変更
CLAUDE_CODE_SUBAGENT_MODELはデフォルト値として機能するように変更(agent 定義のmodel:や spawn 時の明示指定が優先)- Claude 以外のモデルではコミットトレーラーが
Co-Authored-By: Claude Codeに - seat ベースの Enterprise サブスクリプションのデフォルトモデルが Opus 5 に
/effortがモデルごとに effort レベルを保存するように- Claude in Chrome のブラウザ操作が常に Claude Code の権限チェックを通るように
その他の notable な修正
- Bash 権限チェックが
OPTIND=1/0のような算術式代入を自動承認していた問題を修正(承認プロンプトを出すように) - thinking のみの出力後に「text content blocks must be non-empty」で会話が固まる問題を修正
- tmux/SSH 上のバックグラウンドセッションでのテキスト選択、GNU screen でのイタリック表示などを修正
- サンドボックス隔離を弱める server-managed settings に承認を必須化
- バイナリサイズを約 7.5 MB 削減(使用頻度の低い6言語のシンタックスハイライト削除を含む)
原文(Release Notes)
What's changed
- Added
PreModelSwitchandPostModelSwitchhook events (block, confirm, or annotate a model switch);SessionStartresume hooks now receive session staleness and the estimated re-cache cost- Added live streaming of a foreground subagent's tool calls and results to Remote Control clients (background subagents, the default, still show status only)
- Added a Spend limit bar to
/usageand arate_limits.spend_limitstatus line field for developers behind a Claude apps gateway with spend limits- Added a per-session prompt-cache line to
/cost(hit ratio, misses, tokens re-cached, warm/cold) and a matchingprompt_cacheobject for status line scripts- Added
attach,logs,stop,respawn, andrmtoclaude --help; the--resumemessage for a running background session now names the exactclaude attach <id>command- Fixed file tools (Read, Write, Edit) following a symlink swapped inside the working directory after the permission check, which could read or write outside the approved location
- Fixed plugin commands declared in a marketplace entry being able to point outside the plugin directory; such paths are now rejected with a path-traversal error
- Fixed project settings being able to enable detailed beta tracing or raw API body logging, and a lower-scope beta tracing endpoint bypassing an OTLP collector pinned by managed settings or a host app
- Fixed the Workflow tool reading (and quoting in errors) a
scriptPathoutside what the session may read before the permission check ran- Fixed Grep and Glob not applying
Read(...)deny rules to files reached through a symlinked search path- Fixed conversations getting stuck on "text content blocks must be non-empty" errors after a turn where the model produced only thinking
- Fixed the first launch on a fresh install starting in default mode instead of auto mode for accounts whose startup default is auto mode
- Fixed Opus 5 requests failing with "effort … is not supported when thinking is disabled" when effort was xhigh/max and thinking was turned off; effort is now sent as
highin that case- Fixed replying to a message Claude Desktop delivered from another session:
SendMessageto that session id now delivers through Claude Desktop instead of failing with "not reachable"- Fixed TUI lag with many parallel subagents: per-second progress ticks now replace their predecessor instead of piling up in the transcript
- Fixed agent teams: a teammate's final answer not reaching the team lead — it now arrives in the idle notification instead of a content-free "available" notice
- Fixed background subagents being unable to reply to a message from an unnamed sibling or parent agent (
fromwas the agent type, which is not an address)- Fixed managed-settings
disableAutoModearriving mid-session not moving an already-running auto-mode session back to default mode- Fixed a "switch to Opus 1M for 5x more context" tip that appeared even when the current Opus model already has a 1M context window
- Fixed Claude apps gateway sessions treating a stored Anthropic profile (e.g. a Console sign-in) as active: listing it in
/statusand retrying gateway 401s with it, though requests never use it- Fixed cloud sessions telling Claude the model had changed when the host was only setting the session's initial model
- Fixed Remote Control reporting a failure when an organization's policy disables it; it now shows a single quiet notice instead
- Fixed
/mcp reconnecton Remote Control showing a generic withheld-detail error instead of the real remedy when a server was disabled in another session- Fixed
--input-format stream-json: client-injected assistant tool calls sent without a message id were merged into the first one and their results lost, including when resuming older sessions- Fixed session transcripts being silently overwritten when a directory change relocated a session onto an existing same-ID transcript
- Fixed background sessions and their subagents being unable to edit files inside a git worktree they created with
git worktree add- Fixed background sessions occasionally starting without any plugin skills (and staying that way) when another Claude Code process was refreshing the plugin marketplace at the same moment
- Fixed selecting text in an opened background session inside tmux over SSH: it now copies to the tmux buffer like a foreground session instead of falling back to OSC 52
- Fixed SDK and cloud sessions hanging indefinitely when an SDK MCP server's handshake acknowledgment was lost; the wait now times out after 70 seconds and marks only that server failed
- Fixed self-hosted runner leaving a stuck session's Bash tool processes running after the session was force-stopped
- Fixed
/usage-creditsfor Team and Enterprise members whose admin set the org's usage-credit limit to $0: it now offers to ask the admin instead of saying a cap was reached- Fixed
--worktree --tmuxwith a merge-request number on a gitlab.com origin trying a doomed GitHub-style fetch first instead of fetching the GitLab ref directly- Fixed Ctrl+G failing with "Emacs quit unexpectedly" in background sessions for editors that open
/dev/tty, such asemacs -nwandmicro- Fixed an
additionalDirectoriesentry containing a null byte crashing startup, or breaking/add-dirand later settings updates when it came from an SDK host, IDE, or hook; it is now skipped- Fixed the MCP server menu's copy shortcut: it now says how the sign-in URL was copied instead of always claiming success
- Fixed italic text (such as the session recap line) rendering as highlighted blocks in GNU screen and in tmux sessions using a
screenterminal type- Fixed
claude mcp add --headerandclaude mcp add-jsonhelp text naming the wrong transports- Fixed
claude ultrareviewand/ultrareviewwaiting the full 30 minutes when the cloud session fails to start; they now stop early and report the reason- Fixed Bash permission checks auto-approving commands that assign an arithmetic expression to an integer shell variable (e.g.
OPTIND=1/0,RANDOM=2+2); these now prompt for approval- Fixed backgrounded sessions (
←,/background,--bg) losing a Vertex/Bedrock gateway (ANTHROPIC_*_BASE_URL+CLAUDE_CODE_SKIP_*_AUTH) exported in the shell, so every request failed- Fixed
claude --bg --model fableon Max plans stopping to ask for usage credits while the interactive session on the same account still had Fable allowance- Fixed the one-time "make auto mode your default" offer appearing in unattended sessions (e.g. agent-team teammate panes), where a stray keypress could accept it unread
- Fixed the managed-settings approval prompt re-appearing after signing in again to the same Claude apps gateway when the settings are unchanged
- Fixed disabled
/bugand/sharereporting that/feedbackwas disabled; tips,/help, and refusal messages no longer suggest/feedbackwhen an org policy or env var turns it off- Fixed cloud session creation advising GitHub setup after a transient GitHub connection failure — the message now says to retry instead
- Improved CPU usage during turns in interactive sessions by cutting redundant UI re-renders
- Improved install size: the native binary is about 5 MB smaller
- Improved cloud sessions: when the session's network proxy drops a connection during a Bash command, the tool result now names the host and reason instead of only "connection reset"
- Improved
/scheduleto explain that MCP servers configured in Claude Code can't be attached to cloud routines, instead of a bare "No MCP connectors" message- Improved framing of messages from your own subagents: Claude is told the sender is a worker inside this session, not an unrelated Claude session
- Improved the prompt placeholder to read "Message @name…" while viewing a background subagent or fork transcript opened from the subagent panel or
/tasks- Improved sanitization of MCP server names in error messages, menus, and command results
- Improved Amazon Bedrock session start under
CLAUDE_CODE_PROVIDER_MANAGED_BY_HOST(e.g. Claude Desktop): a session given a Bedrock model ID or ARN no longer waits for inference-profile discovery- Improved the managed settings approval dialog to list only the settings that changed since you last approved them
- Improved retry when the model's tool call is malformed: the broken output is now dropped from the retry context, including on Bedrock, Vertex, and Foundry
- Changed
/radioto be available on Bedrock, Vertex AI, Foundry, and Claude Platform on AWS, and when telemetry is disabled- Changed Claude in Chrome so browser actions always go through Claude Code's permission checks, including in sessions with telemetry disabled, which previously used the Chrome extension's own prompts
- Changed
CLAUDE_CODE_SUBAGENT_MODELto set the default subagent model rather than override everything: an agent definition'smodel:and an explicit per-spawn model now take precedence over it- Changed the default commit trailer to
Co-Authored-By: Claude Codewhen the active model isn't a recognized Claude model (e.g. third-party models behind a customANTHROPIC_BASE_URL)- Changed the default model for seat-based Enterprise subscriptions to Opus 5, matching other premium plans
- Changed
/effortto save your default effort level per model, so each model keeps its own setting when you switch- Changed analytics to no longer turn off before sign-in solely because managed settings force gateway login (or cannot be read); they stay off once signed in to the gateway or via
DISABLE_TELEMETRY- Changed the footer PR badge on Bedrock, Vertex, and Foundry, and when telemetry is off, to call the GitHub API directly (via
gh auth token,GH_TOKEN, orGITHUB_TOKEN) instead ofgh pr view- Changed how Bash command output files are created and read back when commands run in the sandbox, so a sandboxed command cannot redirect or replace them
- Changed plugin/LSP install suggestions and the auto-mode default offer to wait until you've sent or cleared what you're typing, so the Enter that sends your prompt can't answer them
- Changed server-managed settings that terminate sandbox TLS, route sandbox traffic through your own proxy, inject credentials, or weaken sandbox isolation to require approval before they apply
- Changed
ANTHROPIC_CUSTOM_HEADERSfrom managed or project settings to require approval when it sets a credential, org/tenant, routing, or API-behavior header (e.g.Authorization,Host)- Changed project-level
.claude/settings.jsonenvto no longer setCLAUDE_CONFIG_DIR,CLAUDE_CODE_TMPDIR, orTMPDIR/TMP/TEMP; set them in your shell, user, or managed settings instead- Removed syntax highlighting for six rarely used languages (1c, gml, isbl, mathematica, maxima, sqf); the binary is 2.5 MB smaller
- [VSCode] Fixed the sign-in screen's "Bedrock, Foundry, or Vertex" button opening the docs at the top of the page instead of the third-party provider setup section
- [VSCode] Changed the Remote Control banner to a footer pill (shown while Remote Control is on or has failed) that opens the session on claude.ai/code; turn it on or off with
/remote-control