
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24052 is a domain validation bypass vulnerability in Anthropic's Claude Code agentic coding tool that allows automatic WebFetch requests to attacker-controlled domains without user consent. The flaw affects all versions of the @anthropic-ai/claude-code npm package prior to v1.0.111. It was discovered by a HackerOne researcher (47sid-praetorian) and disclosed on February 3, 2026. The vulnerability carries a CVSS v4 base score of 7.1 (High) and a CVSS v3.1 base score of 7.4 (High) (GitHub Advisory, Anthropic Advisory).
The root cause is improper input validation (CWE-20) in Claude Code's trusted domain verification mechanism for WebFetch requests, also classified as CWE-601 (URL Redirection to Untrusted Site). The application used a JavaScript startsWith() string comparison to check whether a requested URL belonged to a trusted domain (e.g., docs.python.org, modelcontextprotocol.io). Because startsWith() only checks the beginning of a string rather than performing proper hostname parsing, an attacker could register a domain such as modelcontextprotocol.io.example.com that would pass the validation check. This allows Claude Code to automatically issue HTTP requests to attacker-controlled infrastructure without prompting the user for consent (GitHub Advisory, Anthropic Advisory).
Successful exploitation primarily affects confidentiality: Claude Code can be tricked into silently sending WebFetch requests to attacker-controlled domains, potentially exfiltrating sensitive data such as source code, API keys, environment variables, or other information accessible within the tool's working context. There is no direct integrity or availability impact. Because Claude Code operates as an agentic coding assistant with broad file system and network access, the data exposure risk is significant for developers using it in sensitive environments (GitHub Advisory, Anthropic Advisory).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.018% (5th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires passive user interaction — a user must trigger a WebFetch operation that resolves to the attacker-crafted domain — but requires no privileges or special attacker preconditions beyond registering a lookalike domain (GitHub Advisory).
modelcontextprotocol.io.attacker.com or docs.python.org.evil.com.startsWith(). The attacker's domain passes validation because it starts with the trusted domain string.modelcontextprotocol.io.*, docs.python.org.*) but resolve to unexpected IP addresses or registrars.modelcontextprotocol.io.example.com) originating from developer machines.Anthropic has patched this vulnerability in @anthropic-ai/claude-code version 1.0.111, which replaces the flawed startsWith() domain check with proper hostname-based URL validation. Users on standard Claude Code auto-update have already received this fix. Users performing manual updates should upgrade to v1.0.111 or later immediately via npm update -g @anthropic-ai/claude-code. No configuration-based workaround is available for unpatched versions (GitHub Advisory, Anthropic Advisory).
The vulnerability was reported through HackerOne by researcher 47sid-praetorian, affiliated with Praetorian, and Anthropic credited the researcher in the advisory. Praetorian subsequently published a blog post examining agentic AI security with Claude Code as a case study (Praetorian Blog). Security aggregators and vulnerability databases (CIRCL, VulnDB, GitLab Advisories) indexed the issue shortly after disclosure, and it received coverage from security news outlets including infinitsec.net. Community reaction has been moderate, with the issue noted as a cautionary example of how string-based domain validation is insufficient in agentic AI tools that make autonomous network requests.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."