Skip to content
AnthropicGHSA-5hhx-v7f6-x7gv

Command execution prior to Claude Code startup trust dialog

High7.7CVE-2025-65099 · Published Nov 19, 2025 · updated Dec 22, 2025

When using Claude Code with Yarn installed, Yarn config files can trigger code execution when running yarn --version. This could lead to a bypass of the directory trust dialog in Claude Code, as plugins and yarnPath could be executed prior to the user accepting the risks of working in an untrusted directory. Users on standard Claude Code auto-update will have received this fix automatically. Users performing manual updates are advised to update to the latest version. Thank you to Benjamin Faller, Redguard AG and Michael Hess for reporting this issue!

GitHub advisory

Affected versions

PackageAffectedFixed in
@anthropic-ai/claude-code
npm
< v1.0.39v1.0.39
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-94

More Anthropic advisories

All Anthropic
Advisory
Network Sandboxing Escape
Low1.8Dec 4, 2025
Command Validation Bypass Allows Arbitrary Code Execution
High8.7Dec 3, 2025
Sed Command Validation Bypass Allows Arbitrary File Writes
High8.7Nov 20, 2025
Command execution prior to Claude Code startup trust dialog
High8.7Oct 3, 2025
Permission deny bypass through symlink
Low2.3Oct 3, 2025
Claude Code Vulnerable to Arbitrary Code Execution via Plugin Autoloading with Specific Yarn Versions
High7.7Sep 24, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.