CVE-2026-24052: 
Claude Code vulnerability analysis and mitigation

Overview

CVE-2026-24052 is a domain validation bypass vulnerability in Anthropic's Claude Code agentic coding tool that allows automatic WebFetch requests to attacker-controlled domains without user consent. The flaw affects all versions of the @anthropic-ai/claude-code npm package prior to v1.0.111. It was discovered by a HackerOne researcher (47sid-praetorian) and disclosed on February 3, 2026. The vulnerability carries a CVSS v4 base score of 7.1 (High) and a CVSS v3.1 base score of 7.4 (High) (GitHub Advisory, Anthropic Advisory).

Technical details

The root cause is improper input validation (CWE-20) in Claude Code's trusted domain verification mechanism for WebFetch requests, also classified as CWE-601 (URL Redirection to Untrusted Site). The application used a JavaScript startsWith() string comparison to check whether a requested URL belonged to a trusted domain (e.g., docs.python.org, modelcontextprotocol.io). Because startsWith() only checks the beginning of a string rather than performing proper hostname parsing, an attacker could register a domain such as modelcontextprotocol.io.example.com that would pass the validation check. This allows Claude Code to automatically issue HTTP requests to attacker-controlled infrastructure without prompting the user for consent (GitHub Advisory, Anthropic Advisory).

Impact

Successful exploitation primarily affects confidentiality: Claude Code can be tricked into silently sending WebFetch requests to attacker-controlled domains, potentially exfiltrating sensitive data such as source code, API keys, environment variables, or other information accessible within the tool's working context. There is no direct integrity or availability impact. Because Claude Code operates as an agentic coding assistant with broad file system and network access, the data exposure risk is significant for developers using it in sensitive environments (GitHub Advisory, Anthropic Advisory).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.018% (5th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires passive user interaction — a user must trigger a WebFetch operation that resolves to the attacker-crafted domain — but requires no privileges or special attacker preconditions beyond registering a lookalike domain (GitHub Advisory).

Exploitation steps

  1. Register a lookalike domain: The attacker registers a domain that begins with a string matching a trusted domain in Claude Code's allowlist, such as modelcontextprotocol.io.attacker.com or docs.python.org.evil.com.
  2. Host a malicious endpoint: Set up an HTTP server on the registered domain to log all incoming requests, including any headers, cookies, or body content sent by Claude Code.
  3. Craft a malicious prompt or content: Embed a reference to the attacker-controlled URL in content that Claude Code will process — for example, in a README, a code comment, a documentation link, or a prompt injection within a file being analyzed.
  4. Trigger WebFetch: When the user runs Claude Code against the malicious content, the tool evaluates the URL against its trusted domain list using startsWith(). The attacker's domain passes validation because it starts with the trusted domain string.
  5. Exfiltrate data: Claude Code automatically issues an HTTP request to the attacker's server without user consent, potentially including sensitive context data. The attacker's server logs the request and any exfiltrated information (GitHub Advisory, Anthropic Advisory).

Indicators of compromise

  • Network: Outbound HTTP/HTTPS requests from the developer workstation to domains that superficially resemble trusted Claude Code domains (e.g., modelcontextprotocol.io.*, docs.python.org.*) but resolve to unexpected IP addresses or registrars.
  • Network: DNS queries for subdomains or extended domains of known Claude Code trusted domains (e.g., modelcontextprotocol.io.example.com) originating from developer machines.
  • Logs: Claude Code or system network logs showing WebFetch requests to domains not matching the canonical trusted domain list, particularly those with the trusted domain name as a prefix rather than the full hostname.
  • Process: Unexpected outbound connections initiated by the Node.js process running Claude Code to unfamiliar external hosts during coding sessions.

Mitigation and workarounds

Anthropic has patched this vulnerability in @anthropic-ai/claude-code version 1.0.111, which replaces the flawed startsWith() domain check with proper hostname-based URL validation. Users on standard Claude Code auto-update have already received this fix. Users performing manual updates should upgrade to v1.0.111 or later immediately via npm update -g @anthropic-ai/claude-code. No configuration-based workaround is available for unpatched versions (GitHub Advisory, Anthropic Advisory).

Community reactions

The vulnerability was reported through HackerOne by researcher 47sid-praetorian, affiliated with Praetorian, and Anthropic credited the researcher in the advisory. Praetorian subsequently published a blog post examining agentic AI security with Claude Code as a case study (Praetorian Blog). Security aggregators and vulnerability databases (CIRCL, VulnDB, GitLab Advisories) indexed the issue shortly after disclosure, and it received coverage from security news outlets including infinitsec.net. Community reaction has been moderate, with the issue noted as a cautionary example of how string-based domain validation is insufficient in agentic AI tools that make autonomous network requests.

Additional resources


Source: This report was generated using AI

Related Claude Code vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55607HIGH7.7
  • MinimOS logoMinimOS
  • @anthropic-ai/claude-code
NoYesJun 29, 2026
CVE-2026-40068HIGH7.7
  • MinimOS logoMinimOS
  • @anthropic-ai/claude-code
NoYesMay 05, 2026
CVE-2026-39861HIGH7.7
  • Claude Code logoClaude Code
  • @anthropic-ai/claude-code
NoYesApr 21, 2026
CVE-2026-54316MEDIUM6
  • MinimOS logoMinimOS
  • @anthropic-ai/claude-code
NoYesJun 23, 2026
CVE-2026-46406MEDIUM4.4
  • MinimOS logoMinimOS
  • @anthropic-ai/claude-code
NoYesJun 29, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management