Three de-facto security advisories without a separate advisory surface
What this changes for operators
- Windows operators on 2.1.148 or earlier with PowerShell allowlists, git worktree workflows, or enterprise login pinning should upgrade to 2.1.149+ before deploying new agents.
- Operators monitoring for security-advisory-shape events (RSS, CVE feeds) need to recognize that Anthropic ships these as ordinary changelog entries; the changelog is the de-facto advisory surface.
- Source-contract owners should decide whether to amend
sources/claude-code.ymlto add an explicit security advisory surface or to document the changelog as carrying that role.
Primary sources
- release_note v2.1.149 changelog (PowerShell cd bypass, worktree sandbox scope fix, 2026-05-22) code.claude.com/docs/en/changelog#2-1-149
- release_note v2.1.148 changelog (Vertex AI provider bypass closure, 2026-05-21) code.claude.com/docs/en/changelog#2-1-148
- release_note v2.1.147 changelog (forceLoginOrgUUID, forceLoginMethod enforcement, 2026-05-21) code.claude.com/docs/en/changelog#2-1-147
Signal metadata
Source findings
- Claude Code: Three De-Facto Security Advisories Without an Advisory Surface 2026-05-27-claude-code-powershell-and-worktree-sandbox-fixes
Featured in
- Auto Stops Asking / 2026-05-27
Run: 2026-05-27-weekly-digest-2026-05-13_2026-05-27-frontier-v0
Schema: bitter.frontier_signals.v0 / ID: 2026-05-27-claude-code-powershell-and-worktree-sandbox-fixes
Research evidence and publication history are open in the repository.