cbcvebase.
CVE-2026-54316
published 2026-06-23

CVE-2026-54316: Claude Code is an agentic coding tool. From 0.2.54 until 2.1.163, because the hostname huggingface.co was pre-approved as a bare hostname for the WebFetch…

PriorityP261critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.52%
42.1th percentile
Claude Code is an agentic coding tool. From 0.2.54 until 2.1.163, because the hostname huggingface.co was pre-approved as a bare hostname for the WebFetch tool, any path on that domain—including attacker-controlled model repositories—was auto-approved without a permission prompt or being subject to --allowedTools restrictions. An attacker able to inject untrusted content into a Claude Code context could direct it to issue WebFetch requests against attacker-controlled repository files (e.g. /resolve/main/config.json), which HuggingFace counts as downloads server-side, creating a covert out-of-band channel for encoding and exfiltrating data Claude can access such as files, environment variables, or command output. Reliably exploiting this required the ability to add untrusted content into a Claude Code context window. This vulnerability is fixed in 2.1.163.

Affected

4 ranges
VendorProductVersion rangeFixed in
anthropic-aiclaude-code>= 0.2.54 < 2.1.1632.1.163
anthropicclaude_code>= 0.2.54 < 2.1.1632.1.163
anthropicsclaude-code——
devspacespluginregistry-rhel9——

Detection & IOCsextracted from sources · hover to see the quote

domainhuggingface.co↗
path/resolve/main/config.json↗
  • →Monitor Claude Code (versions 0.2.54–2.1.162) for outbound WebFetch/HTTP requests to huggingface.co paths matching the pattern /resolve/main/* that are not user-initiated, especially to repository paths not referenced in the project codebase — these may indicate covert data exfiltration encoding. ↗
  • →Alert on WebFetch tool invocations targeting huggingface.co that bypass --allowedTools restrictions; in affected versions these requests are auto-approved without a permission prompt, so absence of a user-approval event paired with a huggingface.co fetch is a strong signal. ↗
  • →Inspect Claude Code session context windows for injected untrusted content (e.g. from model cards, README files, or external documents) that contains instructions to fetch huggingface.co URLs — this is the required precondition for exploitation. ↗
  • →Identify claude-code version 2.1.138 deployed in Red Hat OpenShift Dev Spaces pluginregistry-rhel9 containers as a confirmed vulnerable instance requiring prioritized review. ↗
  • ·The pre-approved domain was configured as a bare hostname (huggingface.co) with no path restrictions, meaning ALL paths under that domain were implicitly trusted by the WebFetch tool — detection rules should not assume only specific subpaths are abused. ↗

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv4.06.0MEDIUMCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.