Claude Code is an agentic coding tool. Prior to version 2.0.31, due to an error in sed command parsing, it was possible to bypass the Claude Code read-only validation and write to arbitrary files on the host system. This issue has been patched in version 2.0.31.
References
| Link | Resource |
|---|---|
| https://github.com/anthropics/claude-code/security/advisories/GHSA-7mv8-j34q-vp7q | Vendor Advisory |
Configurations
History
04 Dec 2025, 18:03
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
| References | () https://github.com/anthropics/claude-code/security/advisories/GHSA-7mv8-j34q-vp7q - Vendor Advisory | |
| CPE | cpe:2.3:a:anthropic:claude_code:*:*:*:*:*:node.js:*:* | |
| First Time |
Anthropic
Anthropic claude Code |
21 Nov 2025, 02:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-21 02:15
Updated : 2025-12-04 18:03
NVD link : CVE-2025-64755
Mitre link : CVE-2025-64755
CVE.ORG link : CVE-2025-64755
JSON object : View
Products Affected
anthropic
- claude_code
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
