Back to Database
Status published
High
CVE-2025-64755
@anthropic-ai/claude-code has Sed Command Validation Bypass that Allows Arbitrary File Writes
Vulnerability Description
Claude Code is an agentic coding tool. Prior to version 2.0.31, due to an error in sed command parsing, it was possible to bypass the Claude Code read-only validation and write to arbitrary files on the host system. This issue has been patched in version 2.0.31.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-64755
Credits & Attribution
No credits recorded in the NVD database.
More from anthropics
View All →CVE-2025-66032
Claude Code Command Validation Bypass Allows Arbitrary Code Execution
High
8.7
CVE-2025-65099
Claude Code vulnerable to command execution prior to startup trust dialog
High
7.7
CVE-2025-59829
Claude Code: Permission deny bypass is possible through symlink
Low
2.3
CVE-2025-59828
Claude Code Vulnerable to Arbitrary Code Execution via Plugin Autoloading with Specific Yarn Versions
High
7.7
CVE-2025-59536
Claude Code's startup trust dialog could lead to Command Execution attack
High
8.7
Affected Vendor
anthropics
View all reports →Affected Software
claude-code
Vulnerable Versions:
< 2.0.31
Timeline
Official Publish:
November 21st, 2025
Last Modified:
November 24th, 2025
Added to House:
July 22nd, 2026