跳到正文
原文
Johann Rehberger / Embrace The Red(RSS)·· 2025-08-11AI 评分67

Claude Code 曾可经 DNS 请求外泄敏感数据(CVE-2025-55284)

Claude Code: Data Exfiltration with DNS (CVE-2025-55284)

AI 导读

Johann Rehberger 披露 Claude Code 的高危漏洞 CVE-2025-55284:间接提示词注入可劫持 Claude Code,利用 ping 等 allowlist 命令把 .env 中的 API 密钥嵌入 DNS 请求外泄,无需用户批准。

来源:Johann Rehberger / Embrace The Red(RSS) · embracethered.com