Claude Code v2.1.290, published on 2026-10-05, makes long WebFetch reads visible and readable in parts. It reports unread text after 100,000 characters and accepts an offset for another read, while interactive WebSearch refills at 100 calls per hour instead of stopping after 200 calls. The release also stops project settings from enabling Claude in Chrome and fixes a read-side symlink race on macOS and Windows.
Claude Code 2.1.290 key facts
- GitHub lists v2.1.290 at
2026-10-05T23:33:17Z. Its release page points to commite8ae451. - WebFetch now reports how much page text remains unread after the 100,000-character window and accepts
offsetto continue reading. - Interactive WebSearch now refills at 100 calls per hour.
CLAUDE_CODE_WEB_SEARCH_REFILLS_PER_HOURsets that rate, and0disables refilling. .claude/settings.jsonand.claude/settings.local.jsoncan no longer enable Claude in Chrome. The release names--chrome,/chrome, and user settings as the available paths.- The release fixes an image read on macOS and Windows that could return a file outside the approved path after a link changed during the read.
Claude Code WebFetch now reports unread text
Before v2.1.290, WebFetch silently dropped page text after 100,000 characters. The new result says how much text was unread and accepts an offset, so an agent can ask for the next part instead of treating missing text as missing source material.
The fix does not make WebFetch a raw page downloader. Claude Code still accepts a URL and an extraction prompt, converts HTML responses to Markdown, and, for most fetches, runs that prompt in a separate model call. The documentation also records several limits that remain in place:
- WebFetch refuses
localhostand hostnames without a dot. HTTP URLs are upgraded to HTTPS. - It caches each response for 15 minutes by default.
CLAUDE_CODE_WEBFETCH_CACHE_TTL_MSchanges that period. - A download that has not finished after five minutes fails.
CLAUDE_CODE_WEBFETCH_DEADLINE_MSchanges that limit, and0removes it.
The important change is visibility. A long page can still need several extraction calls, but the tool now tells the agent that it has more text to read.
Claude Code WebSearch now refills its session budget
Claude Code v2.1.290 changes the interactive WebSearch budget from a fixed stop after 200 calls to a budget that refills at 100 calls per hour. CLAUDE_CODE_WEB_SEARCH_REFILLS_PER_HOUR controls the refill rate. Setting it to 0 restores non-refilling behavior.
The environment-variable reference still documents CLAUDE_CODE_MAX_WEB_SEARCHES_PER_SESSION with a default of 200. The tools reference says the count spans the main conversation and its subagents. The release therefore changes how the budget returns; it does not describe unlimited search. Teams that tune search capacity should check both variables.
Claude Code project settings no longer enable Chrome
Claude Code v2.1.290 prevents a repository's project settings from turning on Claude in Chrome. An operator must pass --chrome, run /chrome, or use user settings. That boundary matters because the Chrome documentation says the integration shares the browser's login state and can reach sites already signed in on the user's browser.
The same release gives browser_batch 90 seconds before timeout, up from 60 seconds, and fixes /chrome's "Reconnect extension" option when a previous connection failed.
Claude Code 2.1.290's image-read fix is separate from CVE-2026-103435
The release notes describe a read-side race. On macOS and Windows, an image path approved by the user could be replaced with a link before the read finished, allowing the read to return a file outside the approved path. The release also fixes the same kind of mid-read link change for an @-mention under the read block or --restricted.
GitHub's advisory for CVE-2026-103435 describes a different write-side race. Claude Code checked that an output path was inside the project, then resolved it again at write time. An attacker who could write to the workspace could replace that path with a link and redirect Claude's output outside the project. GitHub lists versions below 2.1.129 as affected and 2.1.129 as patched.
Issue | Operation | Fixed in |
|---|---|---|
v2.1.290 image-read race | Read an approved image or | 2.1.290 |
CVE-2026-103435, GHSA-5j29-h97v-84ch | Write Claude's output through a swapped path | 2.1.129 |
Both bugs involve a path changing between a check and its use. They are different failures and should not be reported as the same vulnerability.
Sources
- Release v2.1.290: https://github.com/anthropics/claude-code/releases/tag/v2.1.290 (read 2026-10-06)
- Release metadata API: https://api.github.com/repos/anthropics/claude-code/releases/tags/v2.1.290 (read 2026-10-06)
- Tools reference: https://code.claude.com/docs/en/tools-reference (read 2026-10-06)
- Environment variables: https://code.claude.com/docs/en/env-vars (read 2026-10-06)
- Claude in Chrome: https://code.claude.com/docs/en/chrome (read 2026-10-06)
- GitHub Security Advisory GHSA-5j29-h97v-84ch: https://github.com/anthropics/claude-code/security/advisories/GHSA-5j29-h97v-84ch (read 2026-10-06)
Last verified: 2026-10-06.