CVE-2026-54316Claude Code WebFetch auto-approval let data out via huggingface.co
Claude Code 0.2.54 up to 2.1.163 auto-approved WebFetch requests to huggingface.co, so attacker content hosted there could pull data out of a session.
What happened
Claude Code versions from 0.2.54 up to, but not including, 2.1.163 let the WebFetch tool reach huggingface.co without asking the user. NVD published the flaw as CVE-2026-54316 in June 2026.
Anyone can publish content on huggingface.co, so an attacker could place content there and use it as an out-of-band channel to move data out of the session.
Why it worked
An allowlisted domain is only as trustworthy as everyone who can publish on it. Auto-approving a multi-tenant host gave any of its users a way out of the session that never triggered a prompt.
What to do
- Update Claude Code to 2.1.163 or later.
- Remove multi-tenant hosts, such as model and code hosting sites, from any auto-approved fetch list.
- Require approval for web fetches in sessions that hold secrets or private code.
- Restrict outbound network at the machine or container level, not only in the agent's settings.
Restrict outbound network accessRequire approval for consequential actions
MCP Python SDK session hijack and cross-session task access
Comment and Control: PR text steals secrets from CI agents
Work through the security checklist →