CVE-2026-54316: Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch

Published Jun 17, 2026
·
Updated

Because the hostname huggingface.co was pre-approved as a bare hostname for the WebFetch tool, any path on that domain—including attacker-controlled model repositories—was auto-approved without a permission prompt or being subject to --allowedTools restrictions. An attacker able to inject untrusted content into a Claude Code context could direct it to issue WebFetch requests against attacker-controlled repository files (e.g. /resolve/main/config.json), which HuggingFace counts as downloads server-side, creating a covert out-of-band channel for encoding and exfiltrating data Claude can access such as files, environment variables, or command output. Reliably exploiting this required the ability to add untrusted content into a Claude Code context window. Users on standard Claude Code auto-update have received this fix already; users performing manual updates are advised to update to the latest version.

Thank you to hackerone.com/novee for reporting this issue.

Other sources

Claude Code is an agentic coding tool. From 0.2.54 until 2.1.163, because the hostname huggingface.co was pre-approved as a bare hostname for the WebFetch tool, any path on that domain—including attacker-controlled model repositories—was auto-approved without a permission prompt or being subject to --allowedTools restrictions. An attacker able to inject untrusted content into a Claude Code context could direct it to issue WebFetch requests against attacker-controlled repository files (e.g. /resolve/main/config.json), which HuggingFace counts as downloads server-side, creating a covert out-of-band channel for encoding and exfiltrating data Claude can access such as files, environment variables, or command output. Reliably exploiting this required the ability to add untrusted content into a Claude Code context window. This vulnerability is fixed in 2.1.163.

MITRE

Affected Software

2 affected componentsFixes available
npm/@anthropic-ai/claude-code>=0.2.54<2.1.163
2.1.163
Anthropic Claude Code Node.js>=0.2.54<2.1.163

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/@anthropic-ai/claude-code to a version that resolves this vulnerability.

    Fixed in 2.1.163
  2. Upgrade

    Upgrade Claude Code to a version that resolves this vulnerability.

    Fixed in 2.1.163

Event History

Jun 17, 2026
Advisory Published
via GitHub·06:06 PM
Data Sourced
via GitHub·06:06 PM
DescriptionWeaknessAffected Software
Jun 23, 2026
CVE Published
via MITRE·05:06 PM
Data Sourced
via MITRE·05:06 PM
DescriptionWeakness
Data Sourced
via NVD·06:18 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-54316?

The severity of CVE-2026-54316 is rated at 55.

2

How do I fix CVE-2026-54316?

To fix CVE-2026-54316, ensure that untrusted model repositories are not auto-approved and implement strict hostname verification.

3

What software does CVE-2026-54316 affect?

CVE-2026-54316 affects the npm package @anthropic-ai/claude-code.

4

What type of vulnerability is CVE-2026-54316?

CVE-2026-54316 is categorized as an information leak vulnerability.

5

When was CVE-2026-54316 published?

CVE-2026-54316 was published on June 17, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203