Meet Corgea at Black Hat, BSides Las Vegas & DEF CON
UNKNOWN npm

@anthropic-ai/claude-code has Sed Command Validation Bypass that Allows Arbitrary File Writes

GHSA-7mv8-j34q-vp7q · CVE-2025-64755

Published · Modified

Description

Due to an error in sed command parsing, it was possible to bypass the Claude Code read-only validation and write to arbitrary files on the host system.

Users on standard Claude Code auto-update will have received this fix automatically. Users performing manual updates are advised to update to the latest version.

Thank you to Adam Chester - SpecterOps for reporting this issue!

Ready to move

Start Securing

Free, no credit card | First findings in minutes