<Vulnerability name="CVE-2026-54316">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-06-23T17:06:16</PublicDate>
    <Bugzilla id="2491853" url="https://bugzilla.redhat.com/show_bug.cgi?id=2491853" xml:lang="en:us">
claude-code: Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>5.3</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-863</CWE>
    <Details xml:lang="en:us" source="Mitre">
Claude Code is an agentic coding tool.  From 0.2.54 until 2.1.163, because the hostname huggingface.co was pre-approved as a bare hostname for the WebFetch tool, any path on that domain—including attacker-controlled model repositories—was auto-approved without a permission prompt or being subject to --allowedTools restrictions. An attacker able to inject untrusted content into a Claude Code context could direct it to issue WebFetch requests against attacker-controlled repository files (e.g. /resolve/main/config.json), which HuggingFace counts as downloads server-side, creating a covert out-of-band channel for encoding and exfiltrating data Claude can access such as files, environment variables, or command output. Reliably exploiting this required the ability to add untrusted content into a Claude Code context window. This vulnerability is fixed in 2.1.163.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in Claude Code, an agentic coding tool. An attacker could exploit a misconfiguration in the tool's web request functionality, known as WebFetch, where the `huggingface.co` domain was pre-approved without proper path restrictions. By injecting untrusted content into a Claude Code session, an attacker could direct the tool to make requests to their controlled files on HuggingFace. This creates a hidden channel to steal sensitive data, such as files or environment variables, that Claude Code can access. The primary impact of this vulnerability is the unauthorized disclosure of information.
    </Details>
    <Statement xml:lang="en:us">
A flaw was found in Claude Code versions 0.2.54 through 2.1.162, where the hostname huggingface.co was pre-approved for the WebFetch tool without path restrictions. An attacker who could inject untrusted content into a Claude Code context window could direct it to make WebFetch requests to attacker-controlled HuggingFace repository files, creating a covert out-of-band channel for exfiltrating data accessible to the Claude Code session. Red Hat OpenShift Dev Spaces ships claude-code version 2.1.138 in its plugin registry container.
    </Statement>
    <Mitigation xml:lang="en:us">
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
    </Mitigation>
    <PackageState cpe="cpe:/a:redhat:openshift_devspaces:3">
        <ProductName>Red Hat OpenShift Dev Spaces</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>devspaces/pluginregistry-rhel9</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-54316
https://nvd.nist.gov/vuln/detail/CVE-2026-54316
https://github.com/anthropics/claude-code/security/advisories/GHSA-fg94-h982-f3mm
    </References>
</Vulnerability>