Claude Code is an agentic coding tool. Prior to version 2.0.31, due to an error in sed command parsing, it was possible to bypass the Claude Code read-only validation and write to arbitrary files on the host system. This issue has been patched in version 2.0.31.
History

Mon, 24 Nov 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Nov 2025 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Anthropics
Anthropics claude Code
Vendors & Products Anthropics
Anthropics claude Code

Fri, 21 Nov 2025 01:45:00 +0000

Type Values Removed Values Added
Description Claude Code is an agentic coding tool. Prior to version 2.0.31, due to an error in sed command parsing, it was possible to bypass the Claude Code read-only validation and write to arbitrary files on the host system. This issue has been patched in version 2.0.31.
Title @anthropic-ai/claude-code has Sed Command Validation Bypass that Allows Arbitrary File Writes
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-11-21T01:13:05.579Z

Updated: 2025-11-24T18:13:06.459Z

Reserved: 2025-11-10T22:29:34.874Z

Link: CVE-2025-64755

cve-icon Vulnrichment

Updated: 2025-11-24T17:17:02.605Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-21T02:15:43.917

Modified: 2025-11-21T15:13:13.800

Link: CVE-2025-64755

cve-icon Redhat

No data.