dotsagent.io
Language:English
CVE-2026-54316

Claude Code WebFetch auto-approval let data out via huggingface.co

Claude Code 0.2.54 up to 2.1.163 auto-approved WebFetch requests to huggingface.co, so attacker content hosted there could pull data out of a session.

What happened

Claude Code versions from 0.2.54 up to, but not including, 2.1.163 let the WebFetch tool reach huggingface.co without asking the user. NVD published the flaw as CVE-2026-54316 in June 2026.

Anyone can publish content on huggingface.co, so an attacker could place content there and use it as an out-of-band channel to move data out of the session.

Why it worked

An allowlisted domain is only as trustworthy as everyone who can publish on it. Auto-approving a multi-tenant host gave any of its users a way out of the session that never triggered a prompt.

What to do

  • Update Claude Code to 2.1.163 or later.
  • Remove multi-tenant hosts, such as model and code hosting sites, from any auto-approved fetch list.
  • Require approval for web fetches in sessions that hold secrets or private code.
  • Restrict outbound network at the machine or container level, not only in the agent's settings.

Restrict outbound network accessRequire approval for consequential actions

Work through the security checklist →

Sources

  1. nvd.nist.gov/vuln/detail/CVE-2026-54316

Independent reference for people who build AI agents. Not affiliated with any vendor named here.

© 2026 DotsAgent · Facts checked October 1, 2026