CVE-2026-54316: Claude Code WebFetch allowlist enabled covert data exfiltration
In Claude Code versions 0.2.54 through 2.1.162, the pre-approved bare hostname huggingface.co allowed any path on that domain—including attacker-controlled model repositories—to be fetched by WebFetch without a permission prompt or --allowedTools enforcement. An attacker able to inject untrusted content into the context could use HuggingFace download counts as an out-of-band channel to exfiltrate files, environment variables or command output; fixed in 2.1.163.
Disclosed 23 June 2026 · Record updated 13 September 2026
Impact
Untrusted content injected into a Claude Code context could trigger auto-approved WebFetch requests to attacker-controlled HuggingFace repository paths, creating a covert channel to encode and exfiltrate data accessible to Claude such as files, environment variables or command output.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-54316
