An Evening with Claude (Code)
ID: 0076b834-b06b-5afb-8dd5-5fc261fbe977
STIX ID: report--0076b834-b06b-5afb-8dd5-5fc261fbe977
Feed Name: XPN InfoSec Blog
Threat Score
**Executive summary:** A researcher from SpecterOps discovered a command-injection and local remote code execution (RCE) vulnerability in Claude Code (assigned CVE-2025-64755) where insufficient validation of shell command patterns—specifically sed expression handling—allowed writing to arbitrary files and achieving code execution; the issue was disclosed to Anthropic and fixed in Claude Code v2.0.31.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
