{"id":"GHSA-vhw5-3g5m-8ggf","summary":"Claude Code has a Domain Validation Bypass which Allows Automatic Requests to Attacker-Controlled Domains","details":"Claude Code contained insufficient URL validation in its trusted domain verification mechanism for WebFetch requests. The application used a `startsWith()` function to validate trusted domains (e.g., `docs.python.org`, `modelcontextprotocol.io`), this could have enabled attackers to register domains like `modelcontextprotocol.io.example.com` that would pass validation. This could enable automatic requests to attacker-controlled domains without user consent, potentially leading to data exfiltration. \n\nUsers on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to the latest version.\n\nThank you to hackerone.com/47sid-praetorian for reporting this issue!","aliases":["CVE-2026-24052"],"modified":"2026-02-03T22:34:25.409039Z","published":"2026-02-03T19:15:59Z","database_specific":{"cwe_ids":["CWE-601"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-02-03T19:15:59Z","nvd_published_at":"2026-02-03T21:16:13Z"},"references":[{"type":"WEB","url":"https://github.com/anthropics/claude-code/security/advisories/GHSA-vhw5-3g5m-8ggf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-24052"},{"type":"PACKAGE","url":"https://github.com/anthropics/claude-code"}],"affected":[{"package":{"name":"@anthropic-ai/claude-code","ecosystem":"npm","purl":"pkg:npm/%40anthropic-ai/claude-code"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.0.111"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-vhw5-3g5m-8ggf/GHSA-vhw5-3g5m-8ggf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}]}