PT-2025-47513 · Yarn+1 · Yarn+1

Published

2025-11-19

·

Updated

2025-11-21

·

CVE-2025-65099

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Claude Code versions prior to 1.0.39
Description Prior to version 1.0.39, Claude Code could be tricked into executing code contained in a project through Yarn plugins before the user accepted the startup trust dialog, when running on a machine with Yarn 3.0 or above. Exploitation required a user to start Claude Code in an untrusted directory while using Yarn 3.0 or higher.
Recommendations Update to version 1.0.39 or later.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-65099
GHSA-5HHX-V7F6-X7GV

Affected Products

Claude-Code
Yarn