Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-54316

Опубликовано: 23 июн. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

Claude Code is an agentic coding tool. From 0.2.54 until 2.1.163, because the hostname huggingface.co was pre-approved as a bare hostname for the WebFetch tool, any path on that domain—including attacker-controlled model repositories—was auto-approved without a permission prompt or being subject to --allowedTools restrictions. An attacker able to inject untrusted content into a Claude Code context could direct it to issue WebFetch requests against attacker-controlled repository files (e.g. /resolve/main/config.json), which HuggingFace counts as downloads server-side, creating a covert out-of-band channel for encoding and exfiltrating data Claude can access such as files, environment variables, or command output. Reliably exploiting this required the ability to add untrusted content into a Claude Code context window. This vulnerability is fixed in 2.1.163.

A flaw was found in Claude Code, an agentic coding tool. An attacker could exploit a misconfiguration in the tool's web request functionality, known as WebFetch, where the huggingface.co domain was pre-approved without proper path restrictions. By injecting untrusted content into a Claude Code session, an attacker could direct the tool to make requests to their controlled files on HuggingFace. This creates a hidden channel to steal sensitive data, such as files or environment variables, that Claude Code can access. The primary impact of this vulnerability is the unauthorized disclosure of information.

Отчет

A flaw was found in Claude Code versions 0.2.54 through 2.1.162, where the hostname huggingface.co was pre-approved for the WebFetch tool without path restrictions. An attacker who could inject untrusted content into a Claude Code context window could direct it to make WebFetch requests to attacker-controlled HuggingFace repository files, creating a covert out-of-band channel for exfiltrating data accessible to the Claude Code session. Red Hat OpenShift Dev Spaces ships claude-code version 2.1.138 in its plugin registry container.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Dev Spacesdevspaces/pluginregistry-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=2491853claude-code: Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch

EPSS

Процентиль: 33%
0.00403
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.1
nvd
около 1 месяца назад

Claude Code is an agentic coding tool. From 0.2.54 until 2.1.163, because the hostname huggingface.co was pre-approved as a bare hostname for the WebFetch tool, any path on that domain—including attacker-controlled model repositories—was auto-approved without a permission prompt or being subject to --allowedTools restrictions. An attacker able to inject untrusted content into a Claude Code context could direct it to issue WebFetch requests against attacker-controlled repository files (e.g. /resolve/main/config.json), which HuggingFace counts as downloads server-side, creating a covert out-of-band channel for encoding and exfiltrating data Claude can access such as files, environment variables, or command output. Reliably exploiting this required the ability to add untrusted content into a Claude Code context window. This vulnerability is fixed in 2.1.163.

CVSS3: 9.1
github
около 2 месяцев назад

Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch

EPSS

Процентиль: 33%
0.00403
Низкий

5.3 Medium

CVSS3