Vulnerability intelligence
CVE-2025-59536
Claude Code is an agentic coding tool. Versions before 1.0.111 were vulnerable to Code Injection due to a bug in the startup trust dialog implementation. Claude Code could be tricked to execute code contained in a project before the user accepted the startup trust dialog. Exploiting this requires a user to start Claude Code in an untrusted directory. Users on standard Claude Code auto-update will have received this fix automatically. Users performing manual updates are advised to update to the latest version. This issue is fixed in version 1.0.111.
CVSS Score
8.7
High
EPSS — Exploit Probability
26%
Riskier than 98% of all CVEs · checked 2026-09-09
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
Patch available
Vendor fix published
6 articles across 4 outlets · first covered May 7, 2026 · latest May 7, 2026
Coverage timeline
-
One‑click TrustFall exploit hijacks Claude Code via bad repowww.darkreading.com · May 7, 2026
-
How AI Coding Tools Crushed the Endpoint Security Fortresswww.darkreading.com · Mar 24, 2026
-
Anthropic’s Claude Code flaws let repos seize PCs, steal keyswww.darkreading.com · Feb 25, 2026
-
Anthropic's Claude Code AI exploited by repos to steal API keyssecurityaffairs.com · Feb 25, 2026
-
Anthropic's Claude Code AI bugs let attackers run code and steal API keysthehackernews.com · Feb 25, 2026
-
Check Point finds API key leak in Anthropic's AI code assistantresearch.checkpoint.com · Feb 25, 2026