claude_code vulnerabilities
CVEs whose affected-version data names the claude_code package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2025-59536High· 8.8PoCClaude Code is an agentic coding tool
Claude Code is an agentic coding tool. Versions before 1.0.111 were vulnerable to Code Injection due to a bug in the startup trust dialog implementation. Claude Code could be tricked to execute code contained in a project before the user…
▾ Midnightanthropic · claude_codeEPSS 27%via NVD
CVE-2025-59829Medium· 6.5Claude Code is an agentic coding tool
Claude Code is an agentic coding tool. Versions below 1.0.120 failed to account for symlinks when checking permission deny rules. If a user explicitly denied Claude Code access to a file and Claude Code had access to a symlink pointing t…
▾ Sunlitanthropic · claude_codeEPSS 0.45%via NVD