Fetching from the wire…
Public story · 2026-08-26 · high
The per-tool auto-approve toggles looked granular but did nothing, so anyone relying on them has been running with blanket MCP approval all along.
Why now: Cline shipped the fix in v4.1.16 on August 26.
Cline pulled the per-tool auto-approve checkboxes for MCP servers in v4.1.16, released August 26, because they never did what they looked like they did.
Anyone who ticked auto-approve for one tool on an MCP server while leaving another unchecked, a read-only lookup left off, a write tool left on, has been running with blanket approval the whole time. Auto-approval for MCP tools is controlled by a single global "Use MCP servers" toggle. The per-tool checkboxes didn't feed into that decision at all.
Cline's release notes call the checkboxes no-ops that implied a granularity the approval path never had. They don't say how long the checkboxes existed before that got noticed, or how many MCP servers ship tools risky enough for the gap to matter.
The same release fixes two other issues. Hooks were resolving their workspace from shared global state in ~/.cline instead of the current VS Code window, which breaks if you run multiple Cline windows on different projects at once. And Cline now redacts credentials embedded in git remote URLs before they reach the model, closing a path where a token pasted into a git remote URL could end up in a prompt.
Each link below shares sources, entities, or timing with this story.
VS Code supports MCP / Shared entities / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (VS Code supports MCP); both cover Anyone, August, Cline, MCP; reported by the same outlet (github.com).
Claude Code uses VS Code / Shared entities / Same source domain / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (Claude Code uses VS Code); both cover August, MCP, VS Code; reported by the same outlet (github.com).
VS Code supports MCP / Shared entities / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (VS Code supports MCP); both cover August, Cline, MCP; reported by the same outlet (github.com).
Claude Code uses VS Code / Shared entities / Same source domain / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (Claude Code uses VS Code); both cover Cline, VS Code; reported by the same outlet (github.com).
Claude Code uses VS Code / Shared entities / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (Claude Code uses VS Code); both cover Anyone, August, MCP; reported by the same outlet (github.com).
VS Code uses Copilot / Shared entities / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (VS Code uses Copilot); both cover August, MCP, VS Code; overlapping topics (august, code).
VS Code supports MCP / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (VS Code supports MCP); both cover Anyone, August, MCP; overlapping topics (anyone, approval, august).
Claude Code uses VS Code / Shared entities / Same source domain / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (Claude Code uses VS Code); both cover Cline, MCP; reported by the same outlet (github.com).