Claude Code is an agentic coding tool. Prior to version 2.0.31, due to an error in sed command parsing, it was possible to bypass the Claude Code read-only validation and write to arbitrary files on the host system. This issue has been patched in version 2.0.31.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-7mv8-j34q-vp7q @anthropic-ai/claude-code has Sed Command Validation Bypass that Allows Arbitrary File Writes
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 21 Nov 2025 01:45:00 +0000

Type Values Removed Values Added
Description Claude Code is an agentic coding tool. Prior to version 2.0.31, due to an error in sed command parsing, it was possible to bypass the Claude Code read-only validation and write to arbitrary files on the host system. This issue has been patched in version 2.0.31.
Title @anthropic-ai/claude-code has Sed Command Validation Bypass that Allows Arbitrary File Writes
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-11-21T01:13:05.579Z

Reserved: 2025-11-10T22:29:34.874Z

Link: CVE-2025-64755

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-11-21T02:15:43.917

Modified: 2025-11-21T02:15:43.917

Link: CVE-2025-64755

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.