@anthropic-ai/claude-code has Sed Command Validation Bypass that Allows Arbitrary File Writes
High severity
GitHub Reviewed
Published
Nov 20, 2025
in
anthropics/claude-code
•
Updated Nov 20, 2025
Description
Published to the GitHub Advisory Database
Nov 20, 2025
Reviewed
Nov 20, 2025
Last updated
Nov 20, 2025
Due to an error in sed command parsing, it was possible to bypass the Claude Code read-only validation and write to arbitrary files on the host system.
Users on standard Claude Code auto-update will have received this fix automatically. Users performing manual updates are advised to update to the latest version.
Thank you to Adam Chester - SpecterOps for reporting this issue!
References