PT-2025-40458 · Anthropic · Claude-Code

Avivdon

·

Published

2025-10-03

·

Updated

2026-05-28

·

CVE-2025-59536

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Claude Code versions prior to 1.0.111
Description Claude Code is an agentic coding tool. A bug in the startup trust dialog implementation allows for code injection, where the tool could be tricked into executing code contained within a project before the user accepts the startup trust dialog. This requires the user to start the tool in an untrusted directory.
Recommendations Update to version 1.0.111 or later.

Exploit

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-59536
GHSA-4FGQ-FPQ9-MR3G

Affected Products

Claude-Code