Claude Code is an agentic coding tool. Versions before 1.0.111 were vulnerable to Code Injection due to a bug in the startup trust dialog implementation. Claude Code could be tricked to execute code contained in a project before the user accepted the startup trust dialog. Exploiting this requires a user to start Claude Code in an untrusted directory. Users on standard Claude Code auto-update will have received this fix automatically. Users performing manual updates are advised to update to the latest version. This issue is fixed in version 1.0.111.
https://www.darkreading.com/cloud-security/amazon-q-vs-extension-flaw-leads-cloud-credential-theft
https://www.wiz.io/blog/amazon-q-vulnerability
https://thehackernews.com/2026/06/amazon-q-developer-flaw-could-let.html
https://www.theregister.com/2026/02/26/clade_code_cves/
https://www.darkreading.com/application-security/flaws-claude-code-developer-machines-risk
https://thehackernews.com/2026/02/claude-code-flaws-allow-remote-code.html
https://blog.checkpoint.com/research/check-point-researchers-expose-critical-claude-code-flaws/
https://github.com/Perufitlife/dotclaude-security
https://github.com/boxed-dev/vibe-coding-security
https://github.com/Razi-Interactive/claude-project-scanner
https://github.com/ezphongdo-cmyk/guardvibe
https://github.com/endiselmanaj/macos-vuln-check
https://github.com/TreRB/ai-ide-config-guard
https://github.com/MQ-06/Claude-Code-Security_ResearchPaper
https://github.com/NetVanguard-cmd/CVE-2025-59536
https://github.com/pathakabhi24/LLM-MCP-Security-Field-Guide
https://github.com/enchanter-ai/hydra
https://github.com/sattyamjjain/agent-audit-kit
https://github.com/Mybodycare/skills-mcps-all-in-one-panel
https://github.com/psnluiz/secure-claude-code
https://github.com/goklab/guardvibe
https://github.com/jnMetaCode/shellward
https://github.com/atiilla/CVE-2026-21852-PoC
https://github.com/jim2478/CVE-Archive
https://github.com/anthropics/claude-code/security/advisories/GHSA-4fgq-fpq9-mr3g
Published: 2025-10-03
Updated: 2025-10-23
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 8.8
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity: High
Base Score: 8.7
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Severity: High
EPSS: 0.26364