Claude Code Sandbox Flaw May Compromise User Secrets
ID: 915ee718-00d2-53ad-a824-f5d3d79d6199
STIX ID: report--915ee718-00d2-53ad-a824-f5d3d79d6199
Feed Name: GBHackers
A null-byte hostname injection in Anthropic's Claude Code sandbox (affecting versions 2.0.24–2.1.89, ~130 releases) allowed attackers to craft SOCKS5 hostnames that pass JavaScript validation but resolve to attacker-controlled domains, enabling full sandbox bypass and silent exfiltration of sensitive data (API keys, env vars, source code, cloud metadata). Anthropic released a fix in v2.1.90 on April 1, 2026 that adds stricter hostname validation, but no public advisory or CVE was published; users are advised to upgrade, audit outbound logs, and rotate credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
