Claude Code could be prompt-injected into leaking secrets over DNS via allowlisted commands (CVE-2025-55284)
2025-claude-code-dns-exfiltration · 2025-06-06
In Claude Code before v1.0.4, an injection planted in a file the tool analyzed could make it abuse network commands that were on the no-approval allowlist (ping, nslookup, host, dig) to encode secrets from .env or /proc/PID/environ into DNS queries and exfiltrate them to an attacker-controlled server (CVE-2025-55284).
System
- Framework
- Claude Code (CLI)
- Tools
- bash, dns, filesystem
- Vendor
- Anthropic
- Autonomy
- supervised-autonomous
Classification
- Primary class
- prompt-injection
- Chain
- prompt-injection/indirect → data-exfiltration/via-tool
- Attack vector
- untrusted-content
- Causation
- entity: human · intentionality: intentional · timing: post-deployment
Trigger
Text in a file that Claude Code analyzed contained injected instructions. Because ping, nslookup, host, and dig were on the allowlist of commands that ran without user approval, the injection could read data from a .env file (or /proc/PID/environ), encode it into a hostname, and issue a command such as a ping — generating a DNS lookup that leaked the data to an external server.
Root cause
Network diagnostic commands were allowlisted to run without approval, and the agent acted on instructions from untrusted file content. Allowlisted commands that can trigger outbound DNS became a covert exfiltration channel that bypassed the normal Bash-tool authorization flow.
Contributing factors
- Commands capable of outbound network activity (ping/nslookup/host/dig) were on the no-approval allowlist.
- The agent treated instructions in analyzed file content as actionable.
- Local secrets (.env, /proc/PID/environ) were reachable by the agent's tools.
Detection
Discovered and disclosed by researcher Johann Rehberger (wunderwuzzi); reported to Anthropic on 2025-05-26.
Recovery
Anthropic fixed the issue in Claude Code v1.0.4, released 2025-06-06; users were advised to upgrade.
Prevention
Keep commands that can cause outbound network requests off no-approval allowlists; treat file/tool content as untrusted; restrict egress and DNS from agent tool sandboxes; scope access to secrets; require approval for actions that can transmit data externally.
Blast radius
- Data
- API keys and environment variables (via .env files and /proc/PID/environ) could be encoded into DNS queries and exfiltrated to an attacker-controlled server. credentials
- User harm
- A disclosed vulnerability with a released fix; no confirmed in-the-wild exploitation was reported. none-reported
- Scope
- Claude Code CLI users before v1.0.4
- Reversibility
- reversible
References
- CWE
- CWE-200
- OWASP LLM
- LLM01 LLM02
- MITRE ATLAS
- AML.T0024 AML.T0051
- Tags
- prompt-injection data-exfiltration dns claude-code allowlist cve
Sources
Cite this incident
Permalink: https://swarmproof.github.io/agent-postmortems/2025-claude-code-dns-exfiltration/
@misc{2025-claude-code-dns-exfiltration,
title = {Claude Code could be prompt-injected into leaking secrets over DNS via allowlisted commands (CVE-2025-55284)},
year = {2025},
howpublished = {agent-postmortems},
url = {https://swarmproof.github.io/agent-postmortems/2025-claude-code-dns-exfiltration/}
}