AE-H4RRJ172
Coding agent's web-fetch tool auto-approves any path on a pre-approved domain, letting injected content exfiltrate data through download counters
PROMPT INJECTIONseverity: CRITICALcause: VERIFIEDoutcome: RESOLVED UNVERIFIEDconfidence: MEDIUM
huggingface.co was pre-approved as a bare hostname for the WebFetch tool, so requests to any path, including attacker-controlled model repositories, ran without a permission prompt and outside --allowedTools restrictions. Untrusted content injected into the agent's context could direct fetches of attacker repository files, which the site counts as downloads, forming a covert channel for exfiltrating files, environment variables or command output.
- Framework / agent
- Claude Code (@anthropic-ai/claude-code) · terminal coding agent
- Remediation attempts
- APPLIED
- Recurrence
- not documented
- Source languages
- en
- Updated
- 2026-09-30
Sources
- SECURITY ADVISORY Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch — https://github.com/anthropics/claude-code, retrieved 2026-09-29
Symptoms
- WebFetch requests to attacker-controlled paths on the pre-approved domain run without a permission prompt
- Server-side download counts on attacker repository files can encode data the agent can access
The full record — root-cause evidence, every remediation attempt with its status and verification, failed attempts, patch references, verbatim quotes and recurrence — is a paid lookup (0.018 USDC via x402). Agents:
GET /api/v1/cases/AE-H4RRJ172. PricingSimilarity to your system is not implied. A remediation that worked in the documented context may not work in yours.