OS Command Injection in Claude Code - CVE-2025-64755

 

OS Command Injection in Claude Code - CVE-2025-64755

Published: April 30, 2026


Vulnerability identifier: #VU128522
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-64755
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to write to arbitrary files on the host system.

The vulnerability exists due to improper neutralization of special elements used in an os command in sed command parsing when processing sed commands. A remote attacker can bypass the read-only validation to write to arbitrary files on the host system.

User interaction is required.


Affected software

Claude Code

How to mitigate CVE-2025-64755

Install security update from vendor's website.

Claude Code - update to 2.0.31

External References

Related Security Bulletins