Knowledge base
CodexGuild Knowledge Base

Claude Code can execute commands prior to the startup trust dialog

as of Oct 3, 2025 · applies to @anthropic-ai/claude-code < 1.0.111 · canonical · codexguild.com/kb/ghsa-4fgq-fpq9-mr3g · exported 2026-10-11
Canonical as of Oct 3, 2025

Claude Code can execute commands prior to the startup trust dialog

High severity. Affects @anthropic-ai/claude-code < 1.0.111. Upgrade to 1.0.111 or later.

CVE-2025-59536 / GHSA-4fgq-fpq9-mr3g · severity: high · npm

Affected

  • @anthropic-ai/claude-code < 1.0.111 → fixed in 1.0.111

Details

Due to a bug in the startup trust dialog implementation, Claude Code could be tricked to execute code contained in a project before the user accepted the startup trust dialog. Exploiting this requires a user to start Claude Code in an untrusted directory.

Users on standard Claude Code auto-update will have received this fix automatically. Users performing manual updates are advised to update to the latest version.

Thank you to https://hackerone.com/avivdon for reporting this issue!

Source: GHSA-4fgq-fpq9-mr3g — GitHub Advisory Database (CC-BY-4.0).