---
id: CVE-2025-59536
title: Claude Code is an agentic coding tool
summary: >-
  Claude Code is an agentic coding tool. Versions before 1.0.111 were vulnerable
  to Code Injection due to a bug in the startup trust dialog implementation.
  Claude Code could be tricked to execute code contained in a project before the
  user…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-94
vendor: anthropic
product: claude_code
affected:
  - claude_code < 1.0.111
patched:
  - claude_code 1.0.111
published: '2025-10-03'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T23:10:00.213'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-59536'
references:
  - url: >-
      https://github.com/anthropics/claude-code/security/advisories/GHSA-4fgq-fpq9-mr3g
    label: security-advisories@github.com
tags:
  - nvd
  - exploit-available
epss: 0.27213
epssPercentile: 0.98011
exploits:
  github: 6
  githubRepos:
    - 'https://github.com/AetherAI3/AETHER-PROTOCOL-P'
    - 'https://github.com/Rohitberiwala/Claude-Code-MCP-Injection-PoC'
    - 'https://github.com/NetVanguard-cmd/CVE-2025-59536'
  checkedAt: '2026-10-08T23:17:21.761Z'
exploitAvailable: true
ingestedAt: '2026-10-08T23:16:47.363Z'
---

## Overview

Claude Code is an agentic coding tool. Versions before 1.0.111 were vulnerable to Code Injection due to a bug in the startup trust dialog implementation. Claude Code could be tricked to execute code contained in a project before the user accepted the startup trust dialog. Exploiting this requires a user to start Claude Code in an untrusted directory. Users on standard Claude Code auto-update will have received this fix automatically. Users performing manual updates are advised to update to the latest version. This issue is fixed in version 1.0.111.

## Affected

- `claude_code < 1.0.111`

## Remediation

Upgrade past the affected range:

- `claude_code 1.0.111`
