Code Injection in Claude Code - CVE-2025-59041
Published: April 30, 2026
Claude Code
Anthropic
Description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper control of code generation in the startup command handling of git config user.email when processing a maliciously configured git email value. A remote attacker can supply a specially crafted git email configuration to execute arbitrary code.
Exploitation can occur before a user accepts the workspace trust dialog.