Due to an error in sed command parsing, it was possible to bypass the Claude Code read-only validation and write to arbitrary files on the host system.
Users on standard Claude Code auto-update will have received this fix automatically. Users performing manual updates are advised to update to the latest version.
Thank you to Adam Chester - SpecterOps for reporting this issue!
{
"cwe_ids": [
"CWE-78"
],
"github_reviewed": true,
"github_reviewed_at": "2025-11-20T21:28:08Z",
"nvd_published_at": "2025-11-21T02:15:43Z",
"severity": "HIGH"
}