Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-54316— Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch

Quick assessment

Affected
anthropics claude-code
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Anthropic Claude Code是美国Anthropic公司的一个终端原生AI编程工具。 Anthropic Claude Code 0.2.54版本至2.1.163之前版本存在安全漏洞,该漏洞源于huggingface.co主机名被预批准为WebFetch工具的裸主机名,导致域内任意路径(包括攻击者控制的模型库)自动批准,可能允许攻击者注入不受信任内容并引导WebFetch请求至攻击者控制的存储库文件,从而创建隐蔽的带外信道,用于编码和渗漏Claude可访问的数据(如文件、环境变量或命令输出)

AI Predicted 7.5 Difficulty: Hard EPSS 0.52% · P42

Affected Version Matrix 1

VendorProduct Version RangeStatus
anthropics claude-code >= 0.2.54, < 2.1.163 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-54316

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch
Source: CVE Program / CVE List V5
Vulnerability Description
Claude Code is an agentic coding tool. From 0.2.54 until 2.1.163, because the hostname huggingface.co was pre-approved as a bare hostname for the WebFetch tool, any path on that domain—including attacker-controlled model repositories—was auto-approved without a permission prompt or being subject to --allowedTools restrictions. An attacker able to inject untrusted content into a Claude Code context could direct it to issue WebFetch requests against attacker-controlled repository files (e.g. /resolve/main/config.json), which HuggingFace counts as downloads server-side, creating a covert out-of-band channel for encoding and exfiltrating data Claude can access such as files, environment variables, or command output. Reliably exploiting this required the ability to add untrusted content into a Claude Code context window. This vulnerability is fixed in 2.1.163.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
宽松定义的白名单
Source: CVE Program / CVE List V5
Vulnerability Title
Anthropic Claude Code 输入验证错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Anthropic Claude Code是美国Anthropic公司的一个终端原生AI编程工具。 Anthropic Claude Code 0.2.54版本至2.1.163之前版本存在安全漏洞,该漏洞源于huggingface.co主机名被预批准为WebFetch工具的裸主机名,导致域内任意路径(包括攻击者控制的模型库)自动批准,可能允许攻击者注入不受信任内容并引导WebFetch请求至攻击者控制的存储库文件,从而创建隐蔽的带外信道,用于编码和渗漏Claude可访问的数据(如文件、环境变量或命令输出)
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
anthropics claude-code >= 0.2.54, < 2.1.163 -

II. Public POCs for CVE-2026-54316

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-54316

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-54316 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-54316

No comments yet


Leave a comment