VDB
Sign up
HIGH

GHSA-vhw5-3g5m-8ggf

Claude Code has a Domain Validation Bypass which Allows Automatic Requests to Attacker-Controlled Domains

Quick fix

GHSA-vhw5-3g5m-8ggf — @anthropic-ai/claude-code: upgrade to the fixed version with the command below.

npm install @anthropic-ai/claude-code@1.0.111

Details

Claude Code contained insufficient URL validation in its trusted domain verification mechanism for WebFetch requests. The application used a `startsWith()` function to validate trusted domains (e.g., `docs.python.org`, `modelcontextprotocol.io`), this could have enabled attackers to register domains like `modelcontextprotocol.io.example.com` that would pass validation. This could enable automatic requests to attacker-controlled domains without user consent, potentially leading to data exfiltration.

Users on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to the latest version.

Thank you to hackerone.com/47sid-praetorian for reporting this issue!

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@anthropic-ai/claude-code
Introduced in: 0Fixed in: 1.0.111
Fixnpm install @anthropic-ai/claude-code@1.0.111

References