
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25723 is a command injection vulnerability in Anthropic's Claude Code agentic coding tool, classified as "Command Injection via Piped sed Command Bypasses File Write Restrictions." Prior to version 2.0.55, Claude Code failed to properly validate commands using piped sed operations combined with the echo command, enabling attackers to bypass file write restrictions and write to sensitive directories such as .claude or paths outside the intended project scope. The vulnerability affects all versions of the @anthropic-ai/claude-code npm package before 2.0.55 and was disclosed on February 6, 2026. It carries a CVSS v3.1 base score of 6.5 (Medium) and a CVSS v4.0 base score of 7.7 (High) (GitHub Advisory, Anthropic Advisory).
The root cause is improper input validation (CWE-20) and improper neutralization of special elements in OS commands (CWE-78). Claude Code's command execution logic did not adequately sanitize or validate piped shell constructs — specifically, sequences combining echo with sed — allowing specially crafted inputs to escape the intended file write sandbox. Exploitation requires the attacker to have the ability to execute commands through Claude Code with the "accept edits" feature enabled, meaning the attack surface is tied to the tool's interactive agentic workflow. The vulnerability was reported via HackerOne by researcher nil221 (Anthropic Advisory, GitHub Advisory).
Successful exploitation allows an attacker to write arbitrary content to sensitive directories — including the .claude configuration folder and paths outside the project scope — bypassing the file write restrictions intended to sandbox Claude Code's operations. This can lead to configuration tampering, persistence mechanisms, and potential lateral movement within the development environment. While confidentiality impact is limited under the CVSS v3.1 scoring, the CVSS v4.0 assessment rates confidentiality, integrity, and availability of the vulnerable system all as High, reflecting the potential for broader system compromise (GitHub Advisory, Feedly).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at the time of disclosure (Feedly). The EPSS score is approximately 0.108–0.123% (31st percentile), indicating a low near-term exploitation probability (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
@anthropic-ai/claude-code) at a version prior to 2.0.55 with the "accept edits" feature enabled in an interactive or automated agentic session.sed operation combined with echo to redirect output to a sensitive path outside the project scope, e.g., echo 'malicious content' | sed 's/x/x/' > ~/.claude/config or a path traversal variant targeting system files.sed construct as a restricted write operation, allowing the command to execute and write to the targeted sensitive directory..claude folder or arbitrary filesystem location), enabling configuration tampering, persistence, or staging for lateral movement (Anthropic Advisory, GitHub Advisory)..claude directory (e.g., ~/.claude/ or project-local .claude/); new or altered files in directories outside the intended project scope created by the Claude Code process.echo ... | sed ... > commands targeting sensitive paths executed under the Claude Code process context; unexpected file write events to configuration directories.sed or echo invocations with output redirection to sensitive directories.Anthropic has released a patch in Claude Code version 2.0.55. Users on standard auto-update configurations received this fix automatically; users performing manual updates should upgrade to version 2.0.55 or later immediately. As a workaround, disable or restrict the "accept edits" feature to trusted users and contexts only, and implement access controls limiting who can execute commands through Claude Code. Monitoring file write activity to sensitive directories such as .claude and paths outside the project scope is also recommended (Anthropic Advisory, GitHub Advisory).
The vulnerability was reported through HackerOne by researcher nil221 and credited in the official Anthropic security advisory. Coverage has appeared on security aggregation sites and threat intelligence feeds shortly after disclosure, with some media attention in the context of broader AI coding agent security concerns (Anthropic Advisory). No significant public researcher commentary or social media debate beyond standard vulnerability tracking has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."