---
title: "Claude Code WebFetch exfiltration (CVE-2026-54316) · DotsAgent"
description: "Claude Code 0.2.54 up to 2.1.163 auto-approved WebFetch requests to huggingface.co, so attacker content hosted there could pull data out of a session."
url: https://dotsagent.io/security/incidents/2026-06-claude-code-webfetch-exfiltration
---

June 2026

CVE-2026-54316

# Claude Code WebFetch auto-approval let data out via huggingface.co

Claude Code 0.2.54 up to 2.1.163 auto-approved WebFetch requests to huggingface.co, so attacker content hosted there could pull data out of a session.

## What happened

Claude Code versions from 0.2.54 up to, but not including, 2.1.163 let the WebFetch tool reach huggingface.co without asking the user. NVD published the flaw as CVE-2026-54316 in June 2026.

Anyone can publish content on huggingface.co, so an attacker could place content there and use it as an out-of-band channel to move data out of the session.

## Why it worked

An allowlisted domain is only as trustworthy as everyone who can publish on it. Auto-approving a multi-tenant host gave any of its users a way out of the session that never triggered a prompt.

## What to do

- Update Claude Code to 2.1.163 or later.
- Remove multi-tenant hosts, such as model and code hosting sites, from any auto-approved fetch list.
- Require approval for web fetches in sessions that hold secrets or private code.
- Restrict outbound network at the machine or container level, not only in the agent's settings.

[Restrict outbound network access](https://dotsagent.io/security#egressControl)[Require approval for consequential actions](https://dotsagent.io/security#humanApproval)

- [MCP Python SDK session hijack and cross-session task access](https://dotsagent.io/security/incidents/2026-06-mcp-python-sdk-session-hijack)

- [Comment and Control: PR text steals secrets from CI agents](https://dotsagent.io/security/incidents/2026-04-comment-and-control-ci-secrets)

[Work through the security checklist →](https://dotsagent.io/security/checklist)

## Sources

1. [nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-54316)/vuln/detail/CVE-2026-54316

Independent reference for people who build AI agents. Not affiliated with any vendor named here.

© 2026 DotsAgent · Facts checked October 1, 2026
