Claude Code is an agentic coding tool. Prior to version 1.0.39, when running on a machine with Yarn 3.0 or above, Claude Code could have been tricked to execute code contained in a project via yarn plugins before the user accepted the startup trust dialog. Exploiting this would have required a user to start Claude Code in an untrusted directory and to be using Yarn 3.0 or above. This issue has been patched in version 1.0.39.
Cite this page
CVE-2025-65099. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2025-65099
Use CWE-94, Anthropic vendor hub and Claude Code product page to widen CVE-2025-65099 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-35022, CVE-2026-35020 and CVE-2026-35021 for nearby disclosures in the same product family.