{"id":"GHSA-j4h9-wv2m-wrf7","summary":"Claude Code vulnerable to arbitrary code execution caused by maliciously configured git email ","details":"At startup, Claude Code constructed a shell command that interpolated the value of `git config user.email` from the current workspace. If an attacker controlled the repository’s Git config (e.g., via a malicious `.git/config`) and set `user.email` to a crafted payload, the unescaped interpolation could trigger arbitrary command execution **before** the user accepted the workspace-trust dialog. The issue affects versions prior to `1.0.105`. The fix in `1.0.105` avoids executing commands built from untrusted configuration and properly validates/escapes inputs.\n\n*   **Patches:** Update to `@anthropic-ai/claude-code` `1.0.105` or later.\n*   **Workarounds:** Open only trusted workspaces and inspect repository `.git/config` before launch; avoid inheriting untrusted Git configuration values.\n\n\u003e Thank you to the NVIDIA AI Red Team for reporting this issue!","aliases":["CVE-2025-59041"],"modified":"2025-09-25T23:42:37Z","published":"2025-09-10T20:29:04Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2025-09-10T20:29:04Z","nvd_published_at":"2025-09-10T16:15:41Z","cwe_ids":["CWE-78","CWE-94"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/anthropics/claude-code/security/advisories/GHSA-j4h9-wv2m-wrf7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-59041"},{"type":"PACKAGE","url":"https://github.com/anthropics/claude-code"},{"type":"WEB","url":"https://www.npmjs.com/package/@anthropic-ai/claude-code/v/1.0.105"}],"affected":[{"package":{"name":"@anthropic-ai/claude-code","ecosystem":"npm","purl":"pkg:npm/%40anthropic-ai/claude-code"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.0.105"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-j4h9-wv2m-wrf7/GHSA-j4h9-wv2m-wrf7.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}