CVE-2026-54316
published 2026-06-23CVE-2026-54316: Claude Code is an agentic coding tool. From 0.2.54 until 2.1.163, because the hostname huggingface.co was pre-approved as a bare hostname for the WebFetch…
PriorityP261critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.52%
42.1th percentile
Claude Code is an agentic coding tool. From 0.2.54 until 2.1.163, because the hostname huggingface.co was pre-approved as a bare hostname for the WebFetch tool, any path on that domain—including attacker-controlled model repositories—was auto-approved without a permission prompt or being subject to --allowedTools restrictions. An attacker able to inject untrusted content into a Claude Code context could direct it to issue WebFetch requests against attacker-controlled repository files (e.g. /resolve/main/config.json), which HuggingFace counts as downloads server-side, creating a covert out-of-band channel for encoding and exfiltrating data Claude can access such as files, environment variables, or command output. Reliably exploiting this required the ability to add untrusted content into a Claude Code context window. This vulnerability is fixed in 2.1.163.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| anthropic-ai | claude-code | >= 0.2.54 < 2.1.163 | 2.1.163 |
| anthropic | claude_code | >= 0.2.54 < 2.1.163 | 2.1.163 |
| anthropics | claude-code | — | — |
| devspaces | pluginregistry-rhel9 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor Claude Code (versions 0.2.54–2.1.162) for outbound WebFetch/HTTP requests to huggingface.co paths matching the pattern /resolve/main/* that are not user-initiated, especially to repository paths not referenced in the project codebase — these may indicate covert data exfiltration encoding. ↗
- →Alert on WebFetch tool invocations targeting huggingface.co that bypass --allowedTools restrictions; in affected versions these requests are auto-approved without a permission prompt, so absence of a user-approval event paired with a huggingface.co fetch is a strong signal. ↗
- →Inspect Claude Code session context windows for injected untrusted content (e.g. from model cards, README files, or external documents) that contains instructions to fetch huggingface.co URLs — this is the required precondition for exploitation. ↗
- →Identify claude-code version 2.1.138 deployed in Red Hat OpenShift Dev Spaces pluginregistry-rhel9 containers as a confirmed vulnerable instance requiring prioritized review. ↗
- ·The pre-approved domain was configured as a bare hostname (huggingface.co) with no path restrictions, meaning ALL paths under that domain were implicitly trusted by the WebFetch tool — detection rules should not assume only specific subpaths are abused. ↗
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv4.06.0MEDIUMCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Anthropic claude-code up to 2.1.162 permissive list of allowed inputs (GHSA-fg94-h982-f3mm)
vuldb·2026-06-23·CVSS 6.0
CVE-2026-54316 [MEDIUM] Anthropic claude-code up to 2.1.162 permissive list of allowed inputs (GHSA-fg94-h982-f3mm)
A vulnerability was found in Anthropic claude-code up to 2.1.162. It has been declared as problematic. This issue affects some unknown processing. Executing a manipulation can lead to permissive list of allowed inputs.
This vulnerability is handled as CVE-2026-54316. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
GHSA
Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch
ghsa·2026-06-17
CVE-2026-54316 [MEDIUM] CWE-183 Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch
Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch
Because the hostname huggingface.co was pre-approved as a bare hostname for the WebFetch tool, any path on that domain—including attacker-controlled model repositories—was auto-approved without a permission prompt or being subject to --allowedTools restrictions. An attacker able to inject untrusted content into a Claude Code context could direct it to issue WebFetch requests against attacker-controlled repository files (e.g. /resolve/main/config.json), which HuggingFace counts as downloads server-side, creating a covert out-of-band channel for encoding and exfiltrating data Claude can access such as files, environment variables, or command output. Reliably exploiting this required the ability to add
Red Hat
claude-code: Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch
vendor_redhat·2026-06-23·CVSS 9.1
CVE-2026-54316 [CRITICAL] CWE-863 claude-code: Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch
claude-code: Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch
Claude Code is an agentic coding tool. From 0.2.54 until 2.1.163, because the hostname huggingface.co was pre-approved as a bare hostname for the WebFetch tool, any path on that domain—including attacker-controlled model repositories—was auto-approved without a permission prompt or being subject to --allowedTools restrictions. An attacker able to inject untrusted content into a Claude Code context could direct it to issue WebFetch requests against attacker-controlled repository files (e.g. /resolve/main/config.json), which HuggingFace counts as downloads server-side, creating a covert out-of-band channel for encoding and exfiltrating data Claude can access such as files, environment var
No detection rules found.
No public exploits indexed.
Checkpoint
10th August – Threat Intelligence Report
blogs_checkpoint·2026-08-10
CVE-2026-12537 10th August – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 10th August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 10th August, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
North Carolina Ports, the US authority operating the ports of Wilmington, Morehead City and others, has suffered a cyberattack that forced some operations onto manual processes. The authority claims it has contained the intrusion, but degraded systems caused delays while affected services were restored.
Ryde, an electric scooter operator in
Hackernews
Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets
blogs_hackernews·2026-08-07·CVSS 7.8
CVE-2026-12537 [HIGH] Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets
A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic's and Google's own coding-agent repositories. On OpenAI's, it was enough to hijack the next agent run.
Novee Security ran the attack against each vendor's agent in the configuration that the vendor ships by default, and presented the work at Black Hat USA on August 5. Two CVEs came out of it. Both are patched.
Gemini CLI carries the worst of the two. CVE-2026-12537 (CVSS 4 score: 10.0) is an OS command injection in the co
Bugzilla
CVE-2026-54316 claude-code: Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch
bugzilla·2026-06-23·CVSS 9.1
CVE-2026-54316 [CRITICAL] CVE-2026-54316 claude-code: Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch
CVE-2026-54316 claude-code: Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch
Claude Code is an agentic coding tool. From 0.2.54 until 2.1.163, because the hostname huggingface.co was pre-approved as a bare hostname for the WebFetch tool, any path on that domain—including attacker-controlled model repositories—was auto-approved without a permission prompt or being subject to --allowedTools restrictions. An attacker able to inject untrusted content into a Claude Code context could direct it to issue WebFetch requests against attacker-controlled repository files (e.g. /resolve/main/config.json), which HuggingFace counts as downloads server-side, creating a covert out-of-band channel for encoding and exfiltrating data Claude can access such as files,
2026-06-23
Published