CVE-2025-59536: Claude Code's startup trust dialog could lead to Command Execution attack
Claude Code is an agentic coding tool. Versions before 1.0.111 were vulnerable to Code Injection due to a bug in the startup trust dialog implementation. Claude Code could be tricked to execute code contained in a project before the user accepted the startup trust dialog. Exploiting this requires a user to start Claude Code in an untrusted directory. Users on standard Claude Code auto-update will have received this fix automatically. Users performing manual updates are advised to update to the latest version. This issue is fixed in version 1.0.111.
Other sources
Due to a bug in the startup trust dialog implementation, Claude Code could be tricked to execute code contained in a project before the user accepted the startup trust dialog. Exploiting this requires a user to start Claude Code in an untrusted directory.
Users on standard Claude Code auto-update will have received this fix automatically. Users performing manual updates are advised to update to the latest version.
Thank you to https://hackerone.com/avivdon for reporting this issue!
— GitHub
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@anthropic-ai/claude-codeto a version that resolves this vulnerability.Fixed in 1.0.111 - Upgrade
Upgrade
Claude Codeto a version that resolves this vulnerability.Fixed in 1.0.111
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59536?
CVE-2025-59536 has been classified as a high severity vulnerability due to its potential for code injection.
How do I fix CVE-2025-59536?
To fix CVE-2025-59536, upgrade Claude Code to version 1.0.111 or later.
What versions of Claude Code are affected by CVE-2025-59536?
Claude Code versions prior to 1.0.111 are affected by CVE-2025-59536.
What type of vulnerability is CVE-2025-59536?
CVE-2025-59536 is a code injection vulnerability.
Can CVE-2025-59536 be exploited remotely?
Yes, CVE-2025-59536 can potentially be exploited remotely if the vulnerable versions are used.