Claude Code Vulnerable to Arbitrary Code Execution via Plugin Autoloading with Specific Yarn Versions
        
  High severity
        
          GitHub Reviewed
      
        Published
          Sep 24, 2025 
          in
          
            anthropics/claude-code
          
          •
          Updated Sep 26, 2025 
      
  
    Give feedback on Dependabot alerts