Claude Code 2.1.196 closes an MCP self-approval hole and binds Remote Control to the Anthropic host
What this changes for operators
- 2.1.196 is a security release:
claude mcp list/getno longer spawn.mcp.jsonservers that a repo self-approves -- closing a path where merely inspecting MCP config in an untrusted repo could launch a repo-declared server. And Remote Control is now disabled whenANTHROPIC_BASE_URLpoints at a non-Anthropic host (org-configurable), so a redirected base URL cannot silently drive remote control. - Upgrade to 2.1.196+ and re-audit MCP trust in any workflow that opens untrusted repositories; if you proxy
ANTHROPIC_BASE_URL, confirm the new Remote Control binding matches your intent.
Primary sources
Signal metadata
Source findings
- 2026-07-01-claude-code-v2-1-196-security-fix-claude-mcp-list-get-no-longer-spaw 2026-07-01-claude-code-v2-1-196-security-fix-claude-mcp-list-get-no-longer-spaw
- 2026-07-01-claude-code-v2-1-196-remote-control-disabled-when-anthropic-base-url 2026-07-01-claude-code-v2-1-196-remote-control-disabled-when-anthropic-base-url
Featured in
- Patched for Whom / 2026-07-01
Run: 2026-07-01-weekly-digest-2026-06-24_2026-07-01-frontier-v0
Schema: bitter.frontier_signals.v0 / ID: 2026-07-01-claude-code-mcp-self-approval-and-remote-binding
Research evidence and publication history are open in the repository.