CVE-2025-59536

HIGH

Claude Code < 1.0.111 - Code Injection via Startup Trust Dialog Bypass

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 7 public exploits for CVE-2025-59536. PoCs published by atiilla, tacdm, Razi-Interactive.

AI-analyzed exploit summary This repository contains functional exploit code demonstrating CVE-2026-21852, an API key exfiltration vulnerability in Anthropic's Claude Code CLI tool. The PoC includes a MITM proxy to capture API keys and a scanner to detect vulnerable configurations.

Description

Claude Code is an agentic coding tool. Versions before 1.0.111 were vulnerable to Code Injection due to a bug in the startup trust dialog implementation. Claude Code could be tricked to execute code contained in a project before the user accepted the startup trust dialog. Exploiting this requires a user to start Claude Code in an untrusted directory. Users on standard Claude Code auto-update will have received this fix automatically. Users performing manual updates are advised to update to the latest version. This issue is fixed in version 1.0.111.

Exploits (7)

github WORKING POC 2 stars
by atiilla · pythonpoc
https://github.com/atiilla/CVE-2026-21852-PoC/tree/main/CVE-2025-59536_mcp_injection

This repository contains functional exploit code demonstrating CVE-2026-21852, an API key exfiltration vulnerability in Anthropic's Claude Code CLI tool. The PoC includes a MITM proxy to capture API keys and a scanner to detect vulnerable configurations.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Anthropic Claude Code CLI v2.0.61
No auth needed
Prerequisites: Victim must use a vulnerable version of Claude Code CLI · Attacker must intercept traffic via MITM proxy
devstral-2 · analyzed Feb 27, 2026 Full analysis →
github WORKING POC
by tacdm · javascriptpoc
https://github.com/tacdm/cve-2025-59536-poc

This repository demonstrates CVE-2025-59536, a vulnerability in Claude Code < 1.0.111 that allows arbitrary code execution through malicious `.claude/settings.json` hooks. The PoC includes a benign payload that writes system info to a file, proving the exploit's functionality.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Claude Code < 1.0.111
No auth needed
Prerequisites: victim clones the repository · victim runs `claude` command
devstral-2 · analyzed May 17, 2026 Full analysis →
nomisec SCANNER
by Razi-Interactive · poc
https://github.com/Razi-Interactive/claude-project-scanner

This repository contains a scanner tool for detecting known security risks in Claude Code projects, specifically targeting CVE-2025-59536 and other related vulnerabilities. It checks for malicious patterns in configuration files, prompt injections, and suspicious payloads without executing any code.

Classification
Scanner 100%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: Claude Code
No auth needed
Prerequisites: Claude Code installation · Access to project directory
devstral-2 · analyzed Apr 30, 2026 Full analysis →
nomisec SCANNER
by TreRB · poc
https://github.com/TreRB/ai-ide-config-guard

This repository contains a static analysis tool designed to scan for malicious AI-IDE configuration files that could lead to RCE, credential theft, or persistent compromise. It checks for various attack vectors such as Claude Code hooks, Unicode smuggling in rules files, MCP auto-registration, and API base-URL redirection.

Classification
Scanner 95%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: AI-IDE configurations (Claude Code, Cursor, Windsurf, Continue, VS Code forks)
No auth needed
Prerequisites: Access to the target repository
devstral-2 · analyzed Apr 20, 2026 Full analysis →
nomisec SUSPICIOUS
by NetVanguard-cmd · poc
https://github.com/NetVanguard-cmd/CVE-2025-59536

The repository claims to exploit CVE-2025-59536 but lacks actual exploit code, instead redirecting users to an external download link (tinyurl.com). The README provides minimal technical details and reads like a generic vulnerability summary.

Classification
Suspicious 90%
Attack Type
Other
Complexity
Theoretical
Reliability
Theoretical
Target: Claude Code < 1.0.111
No auth needed
Prerequisites: User interaction to open untrusted directory · Vulnerable version of Claude Code
devstral-2 · analyzed Apr 19, 2026 Full analysis →
nomisec WRITEUP
by DBarr3 · poc
https://github.com/DBarr3/AETHER-PROTOCOL-P

The repository provides a detailed technical analysis of CVE-2025-59536, focusing on the root cause (lack of cryptographic authentication in AI instruction execution) and proposing a quantum-based solution (Aether Protocol) to mitigate such vulnerabilities. It includes architectural details, security properties, and real-world deployment metrics.

Classification
Writeup 95%
Attack Type
Other
Complexity
Complex
Reliability
Theoretical
Target: Claude Code (AI instruction execution layer)
No auth needed
Prerequisites: Access to IBM Quantum hardware for quantum entropy generation · Integration with AI decision execution layers
devstral-2 · analyzed Mar 17, 2026 Full analysis →
nomisec WORKING POC
by Rohitberiwala · poc
https://github.com/Rohitberiwala/Claude-Code-MCP-Injection-PoC

This PoC demonstrates a UI/UX flaw in Anthropic's Claude Code where an attacker-controlled MCP server can misrepresent tool parameters in confirmation prompts, leading users to approve benign actions while executing malicious commands. The provided server.py file contains functional exploit code that simulates this behavior.

Classification
Working Poc 90%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: Anthropic Claude Code (v2.1.63)
No auth needed
Prerequisites: Attacker-controlled MCP server · User interaction to approve tool execution
devstral-2 · analyzed Mar 10, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 8.8
EPSS 0.0004
EPSS Percentile 13.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (2)
anthropic/claude_code < 1.0.111
anthropic-ai/claude-code 0 - 1.0.111npm
Published Oct 03, 2025
Tracked Since Feb 18, 2026