SB2026043041 - OS Command Injection in Claude Code
Published: April 30, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) OS Command Injection (CVE-ID: CVE-2025-64755)
The vulnerability allows a remote attacker to write to arbitrary files on the host system.
The vulnerability exists due to improper neutralization of special elements used in an os command in sed command parsing when processing sed commands. A remote attacker can bypass the read-only validation to write to arbitrary files on the host system.
User interaction is required.
Remediation
Install update from vendor's website.