CVE-2025-59536 is a high-severity code injection vulnerability (CWE-94) affecting Anthropic Claude Code versions prior to 1.0.111. This flaw allows an attacker to execute arbitrary code from a malicious project before a user accepts the startup trust dialog, provided the user starts Claude Code in an untrusted directory. The vulnerability carries a CVSS score of 8.8 (HIGH), indicating a network-based attack with low complexity, requiring user interaction, and leading to high impacts on confidentiality, integrity, and availability. While not currently in CISA's KEV catalog, its FAUCET Risk Score is 83/100. There is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not actively exploited. However, the vulnerability has garnered significant community discussion (11 mentions) and media coverage, highlighting its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.111CPE matchmatch criteria | cpe:2.3:a:anthropic:claude_code:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.