ClaudeUpdates.dev
Update Claude Code
ClaudeUpdates.dev
390 releases|Latest v2.1.267|Last Update Sep 09, 2026
Update Claude Code
v2.1.263Older
2.1.261
2.1.263
2.1.265
2.1.266
2.1.267
2.1.263
2.1.265
2.1.266
v2.1.266Newer
← Back to all releases

v2.1.265 Claude Code Release Notes

Sep 8, 2026
Claude's Analysisby Sonnet 5
Full Analysis

Major stability pass fixing session-resume corruption, prompt-cache breaks, and Windows sandbox file-access failures, plus a big plugin-system security hardening pass.

Changes
50
Total Changes (vs Average)
3.7×
Version Type
Patch
Release Focus
Bug Fixes
Days Since Prior Release
3
Release # This Month
#7 of 9
Bug Fix Ratio
68%
Post-Release Edits
—
Change Category
Ecosystem Impact
Plugins/Skills has shown up in 6 of the last 10 releases, and this cycle's fixes close symlink-containment and directory-naming security gaps — sustained hardening, not one-off patches.
Key Themes
7Session & resume reliability|11Plugin system hardening|5VS Code & Windows fixes|6MCP, connectors & terminal timing|5Behavior changes worth checking
May Help If You've Noticed
Claude Code freezes or misbehaves when resuming a session after a crash or restart
VS Code's chat sidebar comes back blank after reloading the window
Windows sandbox setups can't read, write, or edit any files at all
Plugins in certain folders or with symlinks silently fail to load
An older MCP server never manages to connect

Changes in Claude Code v2.1.265

Added4 changes

  • •Added user.email and user.groups to the telemetry Claude Desktop and Cowork send through a Claude apps gateway, matching terminal sessions
  • •Added support for pointing --plugin-dir at a folder of plugins: each child folder with a manifest loads, and children added or removed while running are picked up
  • •Added a 1 GB cap on tool results saved to disk; the in-conversation preview says when a saved file was truncated
  • •[VSCode] Added automatic archiving of sessions inactive for a set period (new "Archive inactive sessions" setting, default 14 days)

Improved7 changes

  • •Improved --worktree startup on large repositories: the new worktree is now checked out in parallel (git 2.32+)
  • •Improved /workflows agent detail: tool calls are marked running, failed or done, the subagent's task list is shown when it has one, and Enter unfolds the listed calls with their inputs and results
  • •Improved slash commands typed mid-prompt: matches now show in a list (Tab opens it outside fullscreen) instead of a single suggestion, and a plugin skill is now found by its bare name
  • •Improved remote MCP servers that need sign-in: Claude Code no longer registers an OAuth client with them until you actually authenticate
  • •Improved the time to resume long sessions that read many files
  • •Improved the error shown when an image over the size limits cannot be decoded: it now names the cause and how to fix it instead of only citing the limit
  • •Improved the Artifact tool's read of an artifact someone else wrote: the summary now treats the page as untrusted content and flags embedded instructions rather than relaying them

Fixed34 changes

  • •Fixed resuming a foreground-spawned subagent changing its tool list and system prompt prefix, which broke prompt-cache reuse for that agent
  • •Fixed agent teammates and resumed subagents moving SubagentStart hook context and preloaded skills out of the prompt prefix on later turns, which broke prompt-cache reuse
  • •Fixed resume after the previous process died while a tool was running: the last prompt is no longer rewritten, and the interrupted tool call is kept and marked interrupted
  • •Fixed /model opusplan[1m] being rejected with "Model not found"
  • •Fixed syntax-highlighted code in permission prompts and messages sometimes omitting a character after a Ruby ?, Erlang $, or Perl $ sigil
  • •Fixed the fullscreen transcript jumping by one row whenever the slash-command or @-file suggestion list opened or closed
  • •Fixed a plugin path containing a backslash bypassing the symlink containment check on macOS and Linux
  • •Fixed plugin directories whose names begin with two dots being wrongly refused as outside the plugin root
  • •Fixed VS Code and SDK sessions occasionally requiring re-login when a session was closed while refreshing its token
  • •Fixed Remote Control sessions sending the end-of-turn signal before the reply's last message, which could show a reply as finished in the Claude app before its last part arrived
  • •Fixed background (--bg) sessions occasionally being retired mid-turn when a message arrived just before the idle timeout
  • •Fixed Claude Code's own git status and diff probes running clean filters configured by a nested repository inside the working tree
  • •Fixed the advisor tool and its instructions being re-decided per request from the request's model; the decision is now made once and announced in the conversation when it changes
  • •Fixed artifact publish accepting connector tool names the connector doesn't expose; the publish is now refused when none of the declared tools exist, and warned when only some don't
  • •Fixed /add-dir <subdirectory> refusing to load a subdirectory's agents when managed settings lock only skills to plugins, and promising agents when only agents are locked
  • •Fixed two-key keyboard shortcuts cancelling silently when the second key arrived more than a second later, as happens inside tmux; they now wait 3 seconds and show a notice when they time out
  • •Fixed forked skills (context: fork) not streaming their kickoff prompt and, with --forward-subagent-text, their text turns as progress events in stream-json
  • •Fixed a plugin's default component folder that the OS cannot check, such as a symlink loop, being silently skipped; it is now reported in /plugin with the error code
  • •Fixed the Claude apps gateway's OTLP telemetry relay pausing all forwarding to a collector for 30 seconds after it rejected a few payloads as malformed or too large
  • •Fixed /plugin Discover/Browse and claude plugin list --json --available showing no description or display name for marketplace plugins whose metadata lives only in their plugin.json
  • •Fixed /login showing "no gateway URL is configured" when re-run in a session that signed in to a Claude apps gateway set by managed settings
  • •Fixed /model claiming a model was "saved as your default" when the settings file couldn't be written; it now says the save failed and why
  • •Fixed /clear from Remote Control waiting on SessionStart hooks and on open terminal dialogs before completing
  • •Fixed the /config dialog changing height when switching between its tabs
  • •Fixed resuming a workflow run after its container restarted; a resume whose run journal is missing now fails with a clear error instead of rerunning every agent
  • •Fixed the claude-api skill's error-code reference: model access failures return 404 and unavailable beta headers return 400, not 403
  • •Fixed non-interactive sessions (-p with stream-json input, Agent SDK, cloud sessions) resetting the shell working directory at each new user message; a cd now persists across turns
  • •Fixed MCP servers configured as http that only speak the legacy HTTP+SSE transport never connecting; Claude Code now falls back to SSE as the MCP spec describes
  • •Fixed some claude.ai connectors in cloud sessions showing as needing authentication even though they are connected in claude.ai (servers that answer an unsupported request with HTTP 401)
  • •Fixed remote sessions keeping their sandbox container alive while a connector approval or sign-in link waits for you
  • •Fixed resumed sessions showing long model-facing recovery instructions in "background task didn't finish" notices instead of a short status line
  • •Windows: Fixed Read, Write and Edit refusing every file ("symlink resolution changed after permission was checked") when running inside an AppContainer or restricted-token sandbox
  • •[VSCode] Fixed the sidebar chat coming back blank after Reload Window or a restart when the conversation had been open for more than 10 minutes
  • •[VSCode] Fixed the timeline dot sitting below the text on the "Remote Control is active" message

Changed5 changes

  • •Updated the .claude folder permission option to say what it actually allows: editing files in the project's .claude folder (or ~/.claude) for the session
  • •Changed machines with forceLoginGatewayUrl in managed settings to be Claude apps gateway sessions from startup, like forceLoginMethod: "gateway"; a leftover claude.ai login or API key is not used
  • •Changed image processing to use the runtime's built-in image support; the CLI no longer extracts a native image module to the temp directory
  • •Changed plugin display metadata to prefer the marketplace entry over plugin.json on the Installed tab and claude plugin details, filling gaps from plugin.json
  • •Changed Claude apps gateway sessions to export OpenTelemetry directly to a collector the gateway's managed settings name in OTEL_EXPORTER_OTLP_ENDPOINT, instead of through the gateway's relay; sessions without a named collector still use the relay

← v2.1.263
All Releases
v2.1.266 →