Claude Code v2.1.236
Released Aug 19, 2026 (11 days ago).
48 issues reference this build
39 still open
9 resolved (19%)
"References this build" means the issue body mentions running 2.1.236 (from the
bug-report template). It reflects report volume, not a proven defect count — an issue may mention a
version without being caused by it. First-party data from the anthropics/claude-code tracker.
Top issues reported on v2.1.236
Ranked by community engagement (reactions and comments).
- [BUG] Auto-update to 2.1.237 leaves broken stub on Windows: claude-code-win32-x64@2.1.237 missing from npm registry (incomplete release)
- [Bug] Fable 5 `reasoning_extraction` refusals track a client-injected batching reminder new in 2.1.236 (version bisect + same-day cross-version control)
- [BUG] Non-streaming retry receives event-stream response (HTTP/2 stream mixup, Intel Mac)
- [BUG] Persistent bottom-right notifications ("Update installed · Restart to update") replace the context meter instead of coexisting with it
- 2.1.236 pins the terminal-title busy glyph to ✳ under ALL multiplexers, not just iTerm's tmux -CC
- [Bug] False positive reasoning_extraction flag when searching local Claude Code session transcripts
- SendMessage (cross-session/teammate) silently discards queued messages to a busy session: `queue-operation: remove` instead of `dequeue`
- Unexpected fable safeguard activation
- [BUG] Plugin install from a marketplace "source: url" entry does not clone git submodules — "skills path not found" (planetscale plugin)
- Peer SendMessage reply nudge stamps from= with agent-type name, not reachable session ID, causing infinite unreachable-address loop
- Background Tasks panel shows a CronCreate one-shot job as a recurring 'Loop' after CronList confirms it's deleted
- [BUG] Task store is addressed by session ID, so a new session ID silently strands existing tasks on disk (files intact, TaskList empty)
- Linux sandbox replaces /run/user with an empty tmpfs, so sandboxed commands cannot reach the D-Bus session bus or the system keyring — gh breaks and the only workaround is plaintext credentials
- Claude is terrible.
- Bash run_in_background ignores `timeout` and a never-exiting background task produces no notification
- [Bug] False Positive Detection Issue
- [Bug] Model switching causes error with non-Fable models
- [Bug] False positive crash detection during debugging session
- [Security] Assistant-generated text injected into USER message turn after advisor tool call
- VSCode extension: empty <pre id="claude-error"> forces a permanent 1px horizontal scrollbar in the webview
- Concurrent `claude` sessions racing on npm-global auto-update causes ENOTEMPTY + missing native binary
- [Bug] Repeated false positive errors blocking all prompts
- [Bug] Fable 5 safeguards flag triggering unexpectedly
- [BUG] temp_git_* clone-staging directories survive a successful plugin install and are never swept, even once marked with .orphaned_at
- [MODEL]
- [Bug] Agent excessive token consumption on simple tasks
- [Bug] False positive rate limiting on agent database queries for analytics
- Worktree-isolation guard: string-executor check matches every argument position, case-insensitively
- [Bug] Excessive safety checks interrupting legitimate workflows
- [Bug] Fable 5 [cyber] Safeguard Incorrectly Flags Security Vulnerability Fixes as Attacks
Changelog
What's changed
- Added
ANTHROPIC_DEFAULT_MODELenvironment variable: sets the model new sessions start on, while a/modelpick still overrides it and persists across restarts (unlikeANTHROPIC_MODEL) - Added
notify_when_idleto cross-sessionSendMessage: ask another Claude Code session on this machine to send one notice when it next goes idle — opt-in, one-shot, no polling (macOS and Linux) - Sandbox: on macOS, wildcard read-deny rules (e.g.
**/.env) now take precedence inside allowed read regions, cover matched directories' contents, and can't be bypassed by renaming the denied file - Fixed clipboard copy, background housekeeping, background sessions, and local MCP logs breaking after the directory a session had switched into was removed (since 2.1.229)
- Fixed the fullscreen renderer failing permanently after a single failed start: it now falls back to the classic renderer instead of exiting on every subsequent launch
- Fixed the
/modelpicker rendering taller than the terminal: it now shows only as many models as fit the window, with the rest reachable by scrolling - Fixed
SendMessagecalls being rejected when a malformed closing tag left the message text inside the summary field - Fixed unhandled promise rejections when a subprocess fails to start, for example
powershell.exeon WSL with Windows interop disabled (regression in 2.1.234) - Fixed fullscreen mode sometimes not showing a newly sent message until the next update after the terminal was resized
- Fixed a blank band that could remain above the prompt after clearing a multi-line prompt, and panes not repainting after resizing the terminal away and back, in fullscreen mode
- Fixed the managed-settings approval prompt sometimes not appearing at startup while still capturing the first keypress as approval
- Fixed terminal tab titles jumping in tmux (iTerm tmux integration): the title is now written only when its text changes instead of animating every 960ms
- Fixed an unclear error when the cloud environments list came back empty or malformed
- Fixed the Fable 5 first-time usage-credits prompt auto-selecting the fallback model after 60 seconds with no answer when using Remote Control
- Fixed spinner tips never appearing, with a repeated background error, when the cached guest-pass reward in
~/.claude.jsonwas malformed - Fixed skills hot-reload in SDK/VS Code sessions raising an error on every skills change after the session's working directory was deleted (2.1.229+)
- Fixed self-hosted runner sessions released on idle, retire, or startup timeout occasionally resuming on another runner before the post-session hook had finished
- Fixed the Clawd mascot's eyes and feet rendering unevenly in iTerm2 at some font sizes
- Fixed occasional runaway session recaps: recap text (automatic and
/recap) is now capped at 400 characters, cut at a word boundary - Improved startup performance: the session counter is now written in the background
- Improved auto mode:
Monitorallow rules are now set aside while auto mode is active, so Monitor commands are reviewed the same way Bash commands are - Improved auto mode on Bedrock, Vertex AI, and Foundry, and when telemetry is disabled: the classifier now uses the same defaults as on the Claude API, including severity-scored classification
- Improved auto mode: the git status check can no longer be fooled by a repo's
status.showUntrackedFiles=nosetting into reporting a clean tree - Changed the
/modelpicker to highlight only the newest model's name, so the highlight marks the new release rather than an arbitrary subset of the list /goal: an idle session whose goal is parked behind long-running background work now checks in automatically after 30 minutes (then 1h, 2h) instead of waiting for you to return/usagenow shows the usage-credits spend row for Team and Enterprise members, and shows a capped row at 0% before anything is spent- SIGTERM in print/SDK mode no longer records an interrupted turn or sy