Skip to content
AnthropicGHSA-vhw5-3g5m-8ggf

Domain Validation Bypass Allows Automatic Requests to Attacker-Controlled Domains

High7.1CVE-2026-24052 · Published Feb 3, 2026

Claude Code contained insufficient URL validation in its trusted domain verification mechanism for WebFetch requests. The application used a `startsWith()` function to validate trusted domains (e.g., `docs.python.org`, `modelcontextprotocol.io`), this could have enabled attackers to register domains like `modelcontextprotocol.io.example.com` that would pass validation. This could enable automatic requests to attacker-controlled domains without user consent, potentially leading to data exfiltration. Users on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to the latest version. Thank you to hackerone.com/47sid-praetorian for reporting this issue!

GitHub advisory

Affected versions

PackageAffectedFixed in
@anthropic-ai/claude-code
Product
< v1.0.111v1.0.111
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-20, CWE-601

More Anthropic advisories

All Anthropic

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.