CVE-2025-59041: Anthropic Claude Code

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Claude Code is an agentic coding tool. At startup, Claude Code executed a command templated in with `git config user.email`. Prior to version 1.0.105, a maliciously configured user email in git could be used to trigger arbitrary code execution before a user accepted the workspace trust dialog. Users on standard Claude Code auto-update will have received this fix automatically. Users performing manual updates are advised to update to version 1.0.105 or the latest version.

Affected products

  • Anthropic Claude Code: before 1.0.105 (fixed in 1.0.105)

Published 2025-09-10. Last modified 2026-06-17.