github.com
https://github.com/anthropics/claude-code CVE-2025-64755
HIGH
@anthropic-ai/claude-code has Sed Command Validation Bypass that Allows Arbitrary File Writes
Record summary
CVE-2025-64755 has a selected CVSS score of 8.7 (high).
Description
Claude Code is an agentic coding tool. Prior to version 2.0.31, due to an error in sed command parsing, it was possible to bypass the Claude Code read-only validation and write to arbitrary files on the host system. This issue has been patched in version 2.0.31.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 24, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
claude-codeBrowse anthropics / claude-code | CVE List | < 2.0.31 | affected |
@anthropic-ai/claude-codeBrowse npm / @anthropic-ai/claude-code | GitHub Advisory | Before 2.0.31 · Fixed in 2.0.31 | affected |
References
3github.comConfirmation
https://github.com/anthropics/claude-code/security/advisories/GHSA-7mv8-j34q-vp7q nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-64755