CVE-2025-64755
Severity CVSS v4.0:
HIGH
Type:
CWE-78
OS Command Injections
Publication date:
21/11/2025
Last modified:
04/12/2025
Description
Claude Code is an agentic coding tool. Prior to version 2.0.31, due to an error in sed command parsing, it was possible to bypass the Claude Code read-only validation and write to arbitrary files on the host system. This issue has been patched in version 2.0.31.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:anthropic:claude_code:*:*:*:*:*:node.js:*:* | 2.0.31 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



