Permissive List of Allowed Inputs in Claude Code - CVE-2026-54316
Published: June 18, 2026
Claude Code
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to a permissive allowlist in the WebFetch tool when processing requests to pre-approved huggingface.co paths. A remote attacker can inject untrusted content into a Claude Code context to trigger WebFetch requests to attacker-controlled repository files and disclose sensitive information.
Exploitation requires the ability to add untrusted content into a Claude Code context window, and the issue creates a covert out-of-band exfiltration channel through server-side download requests.