Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch
Vulnerability Description
Claude Code is an agentic coding tool. From 0.2.54 until 2.1.163, because the hostname huggingface.co was pre-approved as a bare hostname for the WebFetch tool, any path on that domain—including attacker-controlled model repositories—was auto-approved without a permission prompt or being subject to --allowedTools restrictions. An attacker able to inject untrusted content into a Claude Code context could direct it to issue WebFetch requests against attacker-controlled repository files (e.g. /resolve/main/config.json), which HuggingFace counts as downloads server-side, creating a covert out-of-band channel for encoding and exfiltrating data Claude can access such as files, environment variables, or command output. Reliably exploiting this required the ability to add untrusted content into a Claude Code context window. This vulnerability is fixed in 2.1.163.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
宽松定义的白名单
Vulnerability Title
Anthropic Claude Code 输入验证错误漏洞
Vulnerability Description
Anthropic Claude Code是美国Anthropic公司的一个终端原生AI编程工具。 Anthropic Claude Code 0.2.54版本至2.1.163之前版本存在安全漏洞,该漏洞源于huggingface.co主机名被预批准为WebFetch工具的裸主机名,导致域内任意路径(包括攻击者控制的模型库)自动批准,可能允许攻击者注入不受信任内容并引导WebFetch请求至攻击者控制的存储库文件,从而创建隐蔽的带外信道,用于编码和渗漏Claude可访问的数据(如文件、环境变量或命令输出)
CVSS Information
N/A
Vulnerability Type
N/A