CVE-2025-59536
largeCode Injection in Anthropic Claude Code Startup Trust Dialog (pre-1.0.111)
Anthropic's Claude Code, an agentic coding tool, contained a code injection flaw (CWE-94) caused by a bug in its startup trust dialog implementation, so all versions before 1.0.111 are affected. An attacker who controls the contents of a project directory — for example a malicious or compromised repository — can get Claude Code to execute code contained in that project before the user has accepted the startup trust dialog, bypassing the prompt meant to gate execution. The trigger is simply a user starting Claude Code in an untrusted directory (user interaction is required, per the CVSS 4.0 vector scored 8.7 High), and a successful attack yields arbitrary code execution with the developer's local privileges, potentially exposing source code and credentials accessible to that account. Users on the standard auto-update channel have already received the fix automatically, while manually updated or version-pinned installations remain exposed until upgraded to 1.0.111 or later. No public proof-of-concept or CISA KEV listing is known, but EPSS assigns a 26.4% probability of exploitation within 30 days (98th percentile), and related research on Claude Code code execution and a similar Amazon Q Developer flaw indicates active researcher and attacker interest in this attack surface.
What to do: Update Claude Code to version 1.0.111 or later; auto-update users should already be patched but should verify the installed version on each workstation, while manually updated or pinned installs must be upgraded explicitly. Until patched, avoid starting Claude Code in untrusted or freshly cloned project directories, and treat trust-dialog prompts on unpatched versions as not yet protective.
| Anthropic Claude Code | All versions before 1.0.111; fixed in 1.0.111 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Claude Code is an agentic coding tool. Versions before 1.0.111 were vulnerable to Code Injection due to a bug in the startup trust dialog implementation. Claude Code could be tricked to execute code contained in a project before the user accepted the startup trust dialog. Exploiting this requires a user to start Claude Code in an untrusted directory. Users on standard Claude Code auto-update will have received this fix automatically. Users performing manual updates are advised to update to the latest version. This issue is fixed in version 1.0.111.
- Vendors
- anthropic
- Products
- claude code
- Weakness
- CWE-94
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X