$ cat anthropics/month/2026-09-01.log
the month in review · September 2026
Sandbox and SDK holes dominate Anthropic's September
By RepoJournal · composed from the cited sources · human-reviewed weekly · methodology
Three command-execution and file-read flaws shipped fixes across the Python agent SDK, Claude Desktop for macOS, and buffa's JSON parser.
Argument Injection via resume Option Allows Arbitrary Command Execution anthropics/claude-agent-sdk-python
Passing a crafted value through the resume option let an attacker run arbitrary commands, an argument injection rather than a parser bug. If you accept resume identifiers from anything a user or upstream service controls, pin the patched SDK release before shipping.
Claude Desktop (macOS): opening a malicious file from a Cowork folder could run commands on the host anthropics/claude-code
Opening a malicious file from a Cowork folder on macOS could execute commands on the host, so the trust boundary is the file's contents, not the folder. Teams running Claude Desktop on macOS should update rather than rely on folder scoping as isolation.
v2.1.284 anthropics/claude-code
Claude Sonnet 5.5 (claude-sonnet-5-5) is now the default Sonnet model on the Anthropic API: 1M context, $2/$10 per Mtok, with cache reads at $0.20 per Mtok. Auto mode also gained a "Yes, but ask again next time" answer for reads outside the working directories, which changes how often you are re-prompted.
v2.1.277 anthropics/claude-code
In a project with no CLAUDE.md, Claude Code now reads AGENTS.md, switchable under "Project instructions" in /config, the release notes say. It is not yet available on Bedrock, Vertex or Foundry, so make that the deciding factor before you migrate a repo's instruction file.
v0.47.0 anthropics/anthropic-sdk-php
by stainless-app[bot]
Usage reports gain Claude Tag category and user breakdowns, mirrored the same day in the Java SDK at 2.61.0 and, on the CLI side, named types for organization compliance settings state. Cost attribution per tag is now something you can read straight off the API rather than reconstruct.
axt-verify v0.1.0 anthropics/axt-verify
The first tagged release of the command-line verifier for the Anthropic Access Transparency log, installable with go install at v0.1.0 and requiring Go 1.26 or newer. The README is explicit about what it checks and what it cannot, which is worth reading before you put it in an evidence path.
docs(changelog): detail the beta files/skills GA-shape change anthropics/anthropic-sdk-go
The Python and Go changelogs now spell out the beta files/skills GA-shape change, including what moved in the beta namespaces and links to migration guides. In short: beta files and skills namespaces use GA shapes and drop dated beta header pins, so update pinned headers as you rebuild against the new SDKs.
$ ls anthropics/month/ # the briefings behind this review
Keep up with Anthropic in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.
fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.
Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.