CVE-2026-25723: 
Claude Code vulnerability analysis and mitigation

Overview

CVE-2026-25723 is a command injection vulnerability in Anthropic's Claude Code agentic coding tool, classified as "Command Injection via Piped sed Command Bypasses File Write Restrictions." Prior to version 2.0.55, Claude Code failed to properly validate commands using piped sed operations combined with the echo command, enabling attackers to bypass file write restrictions and write to sensitive directories such as .claude or paths outside the intended project scope. The vulnerability affects all versions of the @anthropic-ai/claude-code npm package before 2.0.55 and was disclosed on February 6, 2026. It carries a CVSS v3.1 base score of 6.5 (Medium) and a CVSS v4.0 base score of 7.7 (High) (GitHub Advisory, Anthropic Advisory).

Technical details

The root cause is improper input validation (CWE-20) and improper neutralization of special elements in OS commands (CWE-78). Claude Code's command execution logic did not adequately sanitize or validate piped shell constructs — specifically, sequences combining echo with sed — allowing specially crafted inputs to escape the intended file write sandbox. Exploitation requires the attacker to have the ability to execute commands through Claude Code with the "accept edits" feature enabled, meaning the attack surface is tied to the tool's interactive agentic workflow. The vulnerability was reported via HackerOne by researcher nil221 (Anthropic Advisory, GitHub Advisory).

Impact

Successful exploitation allows an attacker to write arbitrary content to sensitive directories — including the .claude configuration folder and paths outside the project scope — bypassing the file write restrictions intended to sandbox Claude Code's operations. This can lead to configuration tampering, persistence mechanisms, and potential lateral movement within the development environment. While confidentiality impact is limited under the CVSS v3.1 scoring, the CVSS v4.0 assessment rates confidentiality, integrity, and availability of the vulnerable system all as High, reflecting the potential for broader system compromise (GitHub Advisory, Feedly).

Exploitability

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at the time of disclosure (Feedly). The EPSS score is approximately 0.108–0.123% (31st percentile), indicating a low near-term exploitation probability (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Exploitation steps

  1. Identify target: Confirm the target is running Claude Code (@anthropic-ai/claude-code) at a version prior to 2.0.55 with the "accept edits" feature enabled in an interactive or automated agentic session.
  2. Craft malicious command: Construct a shell command that uses a piped sed operation combined with echo to redirect output to a sensitive path outside the project scope, e.g., echo 'malicious content' | sed 's/x/x/' > ~/.claude/config or a path traversal variant targeting system files.
  3. Inject via Claude Code interface: Submit the crafted command through the Claude Code command execution interface (e.g., via a prompt or automated task) in a context where the "accept edits" feature will auto-approve the operation.
  4. Bypass file write restriction: Claude Code's insufficient validation fails to detect the piped sed construct as a restricted write operation, allowing the command to execute and write to the targeted sensitive directory.
  5. Achieve objective: The attacker's payload is written to the target path (e.g., .claude folder or arbitrary filesystem location), enabling configuration tampering, persistence, or staging for lateral movement (Anthropic Advisory, GitHub Advisory).

Indicators of compromise

  • File System: Unexpected or modified files in the .claude directory (e.g., ~/.claude/ or project-local .claude/); new or altered files in directories outside the intended project scope created by the Claude Code process.
  • Logs: Shell history or audit logs showing echo ... | sed ... > commands targeting sensitive paths executed under the Claude Code process context; unexpected file write events to configuration directories.
  • Process: Unusual child processes spawned by the Claude Code Node.js process writing to paths outside the project root; sed or echo invocations with output redirection to sensitive directories.

Mitigation and workarounds

Anthropic has released a patch in Claude Code version 2.0.55. Users on standard auto-update configurations received this fix automatically; users performing manual updates should upgrade to version 2.0.55 or later immediately. As a workaround, disable or restrict the "accept edits" feature to trusted users and contexts only, and implement access controls limiting who can execute commands through Claude Code. Monitoring file write activity to sensitive directories such as .claude and paths outside the project scope is also recommended (Anthropic Advisory, GitHub Advisory).

Community reactions

The vulnerability was reported through HackerOne by researcher nil221 and credited in the official Anthropic security advisory. Coverage has appeared on security aggregation sites and threat intelligence feeds shortly after disclosure, with some media attention in the context of broader AI coding agent security concerns (Anthropic Advisory). No significant public researcher commentary or social media debate beyond standard vulnerability tracking has been identified.

Additional resources


Source: This report was generated using AI

Related Claude Code vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55607HIGH7.7
  • MinimOS logoMinimOS
  • @anthropic-ai/claude-code
NoYesJun 29, 2026
CVE-2026-40068HIGH7.7
  • MinimOS logoMinimOS
  • @anthropic-ai/claude-code
NoYesMay 05, 2026
CVE-2026-39861HIGH7.7
  • Claude Code logoClaude Code
  • @anthropic-ai/claude-code
NoYesApr 21, 2026
CVE-2026-54316MEDIUM6
  • MinimOS logoMinimOS
  • @anthropic-ai/claude-code
NoYesJun 23, 2026
CVE-2026-46406MEDIUM4.4
  • MinimOS logoMinimOS
  • @anthropic-ai/claude-code
NoYesJun 29, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management