Skip to content
AnthropicGHSA-9gqj-5w7c-vx47

Network Sandboxing Escape

Low1.8CVE-2025-66479 · Published Dec 4, 2025

Due to a bug in sandboxing logic, `sandbox-runtime` did not properly enforce a network sandbox if the sandbox policy did not configure any allowed domains. This could allow sandboxed code to make network requests outside of the sandbox. A patch for this was released in v0.0.16. Thank you to https://github.com/bendrucker for reporting this issue!

GitHub advisory

Affected versions

PackageAffectedFixed in
@anthropic-ai/sandbox-runtime
npm
< 0.0.160.0.16
Details and references
CVSS 4.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Severity from
GitHub (reviewed advisory)

More Anthropic advisories

All Anthropic
Advisory
Path Restriction Bypass via ZSH Clobber Allows Arbitrary File Writes
High7.7Feb 3
Domain Validation Bypass Allows Automatic Requests to Attacker-Controlled Domains
High7.1Feb 3
Anthropic: information disclosure
Medium5.3Jan 20
Command Validation Bypass Allows Arbitrary Code Execution
High8.7Dec 3, 2025
Sed Command Validation Bypass Allows Arbitrary File Writes
High8.7Nov 20, 2025
Command execution prior to Claude Code startup trust dialog
High7.7Nov 19, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.