{"id":"CVE-2026-24052","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-24052","summary":"Claude Code has a Domain Validation Bypass which Allows Automatic Requests to Attacker-Controlled Domains","details":"Claude Code contained insufficient URL validation in its trusted domain verification mechanism for WebFetch requests. The application used a `startsWith()` function to validate trusted domains (e.g., `docs.python.org`, `modelcontextprotocol.io`), this could have enabled attackers to register domains like `modelcontextprotocol.io.example.com` that would pass validation. This could enable automatic requests to attacker-controlled domains without user consent, potentially leading to data exfiltration. \n\nUsers on standard Claude Code auto-update have received this fix already. Users performing manual updates are advised to update to the latest version.\n\nThank you to hackerone.com/47sid-praetorian for reporting this issue!","published":"2026-02-03T19:15:59Z","modified":"2026-02-03T22:34:25.409039Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@anthropic-ai/claude-code","fixedVersion":"1.0.111"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/anthropics/claude-code/security/advisories/GHSA-vhw5-3g5m-8ggf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-24052"},{"type":"PACKAGE","url":"https://github.com/anthropics/claude-code"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-02-03T22:34:25.409039Z"}}