CVE-2025-64755: @anthropic-ai/claude-code has Sed Command Validation Bypass that Allows Arbitrary File Writes
Claude Code is an agentic coding tool. Prior to version 2.0.31, due to an error in sed command parsing, it was possible to bypass the Claude Code read-only validation and write to arbitrary files on the host system. This issue has been patched in version 2.0.31.
Other sources
Due to an error in sed command parsing, it was possible to bypass the Claude Code read-only validation and write to arbitrary files on the host system.
Users on standard Claude Code auto-update will have received this fix automatically. Users performing manual updates are advised to update to the latest version.
Thank you to Adam Chester - SpecterOps for reporting this issue!
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64755?
CVE-2025-64755 is classified as a high-severity vulnerability due to its potential for unauthorized file writes.
How do I fix CVE-2025-64755?
To fix CVE-2025-64755, update to version 2.0.31 of the @anthropic-ai/claude-code package.
What does CVE-2025-64755 affect?
CVE-2025-64755 affects the @anthropic-ai/claude-code package, specifically versions prior to 2.0.31.
What causes CVE-2025-64755?
CVE-2025-64755 is caused by an error in sed command parsing that allows bypassing read-only validation.
Who is impacted by CVE-2025-64755?
Users of the @anthropic-ai/claude-code package who perform manual updates are primarily impacted by CVE-2025-64755.