Follow Discord
Sweep 29 Sep 2026 · 18:10Z Build v2.1.285 506 read Stable v2.1.280 Latest v2.1.285 Next v2.1.285 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.285 ·

Merging configuration data now ignores keys named __proto__

When Claude Code merges structured data, it now drops any key named __proto__

You'll notice Improvements
JSON All of v2.1.285
You'll noticeTier: how much it should matter to you
1Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
SettingsArea: what it touches
ImprovementsKind: in v2.1.285,
ImprovementsSection of the release
What

Claude Code sometimes combines pieces of structured data, such as settings described by a schema (a description of what the data should look like). When it does, it now deletes any entry named __proto__ and skips it while combining.

Why

In JavaScript, the language Claude Code is written in, __proto__ is a special name. Data that contains it can alter how every object behaves, a kind of attack known as prototype pollution. Skipping it closes off that attack.

See this entry in the whole of v2.1.285 →

Feedback