{"id":"CVE-2025-65099","summary":"Claude Code vulnerable to command execution prior to startup trust dialog","details":"Claude Code is an agentic coding tool. Prior to version 1.0.39, when running on a machine with Yarn 3.0 or above, Claude Code could have been tricked to execute code contained in a project via yarn plugins before the user accepted the startup trust dialog. Exploiting this would have required a user to start Claude Code in an untrusted directory and to be using Yarn 3.0 or above. This issue has been patched in version 1.0.39.","aliases":["GHSA-5hhx-v7f6-x7gv"],"modified":"2026-03-13T03:38:35.080924Z","published":"2025-11-19T17:35:17.349Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/65xxx/CVE-2025-65099.json","cwe_ids":["CWE-94"],"cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/65xxx/CVE-2025-65099.json"},{"type":"ADVISORY","url":"https://github.com/anthropics/claude-code/security/advisories/GHSA-5hhx-v7f6-x7gv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-65099"}],"affected":[{"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-65099.json","unresolved_ranges":[{"events":[{"introduced":"0"},{"fixed":"1.0.39"}]}]}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}