CVE-2026-24052Disclosure(anthropic / claude_code)

LOWCVSS 7.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Claude Code is an agentic coding tool. Prior to version 1.0.111, Claude Code contained insufficient URL validation in its trusted domain verification mechanism for WebFetch requests. The application used a startsWith() function to validate trusted domains (e.g., docs.python.org, modelcontextprotocol.io), this could have enabled attackers to register domains like modelcontextprotocol.io.example.com that would pass validation. This could enable automatic requests to attacker-controlled domains without user consent, potentially leading to data exfiltration. This issue has been patched in version 1.0.111.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-601

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • claude_code

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-02-03); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
claude_code

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-03: 1Mentions · 2026-02-04: 1Mentions · 2026-03-18: 1Technical Details · 2026-02-03: 1Technical Details · 2026-03-18: 102-0302-0403-18
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • cvereports@_cvereports
    Disclosure

    CVE-2026-24052: Claude Code: When 'Trusted' Domains Turn Traitor In the race to build autonomous AI agents, Anthropic's Claude Code stumbled over one of the oldest hurdles in web security: string matching. CVE-2026-24052 describes a critical logic fla... https://cvereports.com/reports/CVE-2026-24052

    Post summary

    The text announces CVE-2026-24052 as a critical logic flaw in Anthropic’s Claude Code, but provides no PoC, exploit details, patch, or technical specifics.

    1000065
    27 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Disclosure

    TRC analysis shows agentic AI tools face unique attack vectors. Claude Code's domain validation bypass (CVE-2026-24052) allowed attackers to exfiltrate data through subdomain spoofing without user consent. Runtime egress controls help contain such automated data flows. #ZeroTrust 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/claude-code-2026-domain-validation-bypass

    Post summary

    The passage reports the discovery of a domain validation bypass (CVE‑2026‑24052) in Claude Code that allows data exfiltration through subdomain spoofing, with an analysis link but no evidence of active exploitation or patch availability.

    0000079
    1.9K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24052 Claude Code is an agentic coding tool. Prior to version 1.0.111, Claude Code contained insufficient URL validation in its trusted domain verification mechanism for We… https://www.cve.org/CVERecord?id=CVE-2026-24052

    Post summary

    The post announces CVE‑2026‑24052, describing insufficient URL validation in Claude Code's trusted domain verification as the vulnerability.

    00000271
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appanthropicclaude_code-node.js-

Explore more