logo

An Evening with Claude (Code)

ID: 0076b834-b06b-5afb-8dd5-5fc261fbe977

STIX ID: report--0076b834-b06b-5afb-8dd5-5fc261fbe977

Feed Name: XPN InfoSec Blog

Threat Score
70/100

Date Published: 2025-11-29

Date Updated: 2026-07-27

...
...

**Executive summary:** A researcher from SpecterOps discovered a command-injection and local remote code execution (RCE) vulnerability in Claude Code (assigned CVE-2025-64755) where insufficient validation of shell command patterns—specifically sed expression handling—allowed writing to arbitrary files and achieving code execution; the issue was disclosed to Anthropic and fixed in Claude Code v2.0.31.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.