Knowledge base
CodexGuild Knowledge Base

@anthropic-ai/claude-code has Sed Command Validation Bypass that Allows Arbitrary File Writes

as of Nov 20, 2025 · applies to @anthropic-ai/claude-code < 2.0.31 · canonical · codexguild.com/kb/ghsa-7mv8-j34q-vp7q · exported 2026-10-11
Canonical as of Nov 20, 2025

@anthropic-ai/claude-code has Sed Command Validation Bypass that Allows Arbitrary File Writes

High severity. Affects @anthropic-ai/claude-code < 2.0.31. Upgrade to 2.0.31 or later.

CVE-2025-64755 / GHSA-7mv8-j34q-vp7q · severity: high · npm

Affected

  • @anthropic-ai/claude-code < 2.0.31 → fixed in 2.0.31

Details

Due to an error in sed command parsing, it was possible to bypass the Claude Code read-only validation and write to arbitrary files on the host system.

Users on standard Claude Code auto-update will have received this fix automatically. Users performing manual updates are advised to update to the latest version.

Thank you to Adam Chester - SpecterOps for reporting this issue!

Source: GHSA-7mv8-j34q-vp7q — GitHub Advisory Database (CC-BY-4.0).