Skip to content
AnthropicGHSA-7mv8-j34q-vp7q

Sed Command Validation Bypass Allows Arbitrary File Writes

High8.7CVE-2025-64755 · Published Nov 20, 2025

Due to an error in sed command parsing, it was possible to bypass the Claude Code read-only validation and write to arbitrary files on the host system. Users on standard Claude Code auto-update will have received this fix automatically. Users performing manual updates are advised to update to the latest version. Thank you to Adam Chester - SpecterOps for reporting this issue!

GitHub advisory

Affected versions

PackageAffectedFixed in
@anthropic-ai/claude-code
npm
< v2.0.31v2.0.31
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-78

More Anthropic advisories

All Anthropic
Advisory
Network Sandboxing Escape
Low1.8Dec 4, 2025
Command Validation Bypass Allows Arbitrary Code Execution
High8.7Dec 3, 2025
Command execution prior to Claude Code startup trust dialog
High7.7Nov 19, 2025
Command execution prior to Claude Code startup trust dialog
High8.7Oct 3, 2025
Permission deny bypass through symlink
Low2.3Oct 3, 2025
Claude Code Vulnerable to Arbitrary Code Execution via Plugin Autoloading with Specific Yarn Versions
High7.7Sep 24, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.