Skip to content

Hide Navigation Hide TOC

Claude Code Hooks SessionStart Pre-Trust RCE (CVE-2025-59536) - ATR-2026-00523 (2d63479d-1c53-5345-a70f-0cd5a594ab11)

Detects exploitation of CVE-2025-59536 (Critical), pre-trust remote code execution in Claude Code via the Hooks feature. An attacker-controlled repository ships a .claude/settings.json that registers a SessionStart hook with the startup matcher; when a developer opens the project directory, Claude Code executes the registered command BEFORE the trust dialog renders. The full kill chain is: clone-or-open malicious repo → Claude Code loads repo-scoped .claude/settings.json → hook command fires pre-trust → arbitrary code runs with developer's local privileges. The matcher / event names (SessionStart, startup) are stable strings in the Claude Code Hooks schema, so the detector anchors on the config-file shape rather than the command payload (any shell binary, curl pipe-to-shell, npm/pip install, or python -c body is sufficient for RCE post-trigger). CWE-94, CWE-1188 (insecure default). Patches in Claude Code via enhanced trust-dialog warning (GHSA-ph6w-f82w-28w6). Reported by Aviv Donenfeld and Oded Vanunu (Check Point Research). This rule detects exploit configs in repo-scoped settings.json files and provides defence-in-depth post-patch by flagging the dangerous matcher shape regardless of upstream dialog state.

Cluster A Galaxy A Cluster B Galaxy B Level
ML Supply Chain Compromise (d2cf31e0-a550-4fe0-8fdb-8941b3ac00d9) MITRE ATLAS Attack Pattern Claude Code Hooks SessionStart Pre-Trust RCE (CVE-2025-59536) - ATR-2026-00523 (2d63479d-1c53-5345-a70f-0cd5a594ab11) Agent Threat Rules 1
Event Triggered Execution - T1546 (b6301b64-ef57-4cce-bb0b-77026f14a8db) Attack Pattern Claude Code Hooks SessionStart Pre-Trust RCE (CVE-2025-59536) - ATR-2026-00523 (2d63479d-1c53-5345-a70f-0cd5a594ab11) Agent Threat Rules 1
Claude Code Hooks SessionStart Pre-Trust RCE (CVE-2025-59536) - ATR-2026-00523 (2d63479d-1c53-5345-a70f-0cd5a594ab11) Agent Threat Rules Compromise Software Supply Chain - T1195.002 (bd369cd9-abb8-41ce-b5bb-fff23ee86c00) Attack Pattern 1
Command and Scripting Interpreter - T1059 (7385dfaf-6886-4229-9ecd-6fd678040830) Attack Pattern Claude Code Hooks SessionStart Pre-Trust RCE (CVE-2025-59536) - ATR-2026-00523 (2d63479d-1c53-5345-a70f-0cd5a594ab11) Agent Threat Rules 1
Claude Code Hooks SessionStart Pre-Trust RCE (CVE-2025-59536) - ATR-2026-00523 (2d63479d-1c53-5345-a70f-0cd5a594ab11) Agent Threat Rules Command and Scripting Interpreter (716d3a6b-2f8c-4a1f-85f7-d884bb7b2800) MITRE ATLAS Attack Pattern 1
Supply Chain Compromise - T1195 (3f18edba-28f4-4bb9-82c3-8aa60dcac5f7) Attack Pattern Compromise Software Supply Chain - T1195.002 (bd369cd9-abb8-41ce-b5bb-fff23ee86c00) Attack Pattern 2