Skip to content
CVE-2026-25723

CVE-2026-25723

www.sentinelone.com • April 30, 2026

Claude Code, an agentic coding tool developed by Anthropic, contains an improper input validation vulnerability in versions prior to 2.0.55 . The vulnerability exists in the command validation logic, which failed to properly validate commands using piped sed operations with the echo command. This security flaw allows attackers to bypass file write restrictions and write to sensitive directories, including the .claude folder and paths outside the intended project scope.

Attackers can bypass file write restrictions to modify sensitive configuration files and write to directories outside the project scope, potentially leading to arbitrary file write and system compromise.

This vulnerability stems from improper input validation (CWE-20) in the command execution pipeline of Claude Code. The application's security controls designed to prevent file writes to restricted directories can be circumvented through specially crafted command chains that combine echo and piped sed operations.

The flaw is particularly significant because it undermines the sandboxing protections that Claude Code relies on to safely execute user-requested file operations. When the "accept edits" feature is enabled, the application should restrict file modifications to the designated project directory. However, the validation logic fails to account for command chaining scenarios involving sed with pipe redirection, allowing writes to escape the intended boundaries.

The attack requires network access and some user interaction (accepting the edit), but no special privileges are required to exploit this vulnerability once an attacker can influence the commands executed through Claude Code.

The root cause is inadequate input validation in the command sanitization layer. The validation logic did not properly parse and evaluate command pipelines involving shell redirection operators combined with text processing utilities like sed. This allowed attackers to construct command sequences that appeared benign to the validator but resulted in file writes to unauthorized locations when executed.

The attack vector is network-based, requiring the attacker to have the ability to execute commands through Claude Code. Exploitation requires the "accept edits" feature to be enabled, which is the mechanism that allows Claude Code to make file modifications. An attacker could craft malicious input that, when processed by Claude Code, would execute a command pipeline that writes content to sensitive directories like .claude (containing configuration and credentials) or paths outside the project scope entirely.

The vulnerability could be triggered through:

Anthropic has released version 2.0.55 of Claude Code which addresses this vulnerability. The patch improves the command validation logic to properly handle piped sed operations and other command chaining scenarios that could bypass file write restrictions.

For detailed information the security fix, refer to the GitHub Security Advisory GHSA-mhg7-666j-cqg4 .

Disclaimer : This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Extracted Entities

Attack Types (1)

MITRE ATT&CK (1)