Claude Code can execute commands prior to the startup trust dialog
Description
Published by the National Vulnerability Database
Oct 3, 2025
Published to the GitHub Advisory Database
Oct 3, 2025
Reviewed
Oct 3, 2025
Last updated
Oct 3, 2025
Due to a bug in the startup trust dialog implementation, Claude Code could be tricked to execute code contained in a project before the user accepted the startup trust dialog. Exploiting this requires a user to start Claude Code in an untrusted directory.
Users on standard Claude Code auto-update will have received this fix automatically. Users performing manual updates are advised to update to the latest version.
Thank you to https://hackerone.com/avivdon for reporting this issue!
References