agent-postmortems a structured database of real AI-agent failures

← all incidents

hazard high confidence: confirmed status: final

Claude Code could be prompt-injected into leaking secrets over DNS via allowlisted commands (CVE-2025-55284)

2025-claude-code-dns-exfiltration · 2025-06-06

In Claude Code before v1.0.4, an injection planted in a file the tool analyzed could make it abuse network commands that were on the no-approval allowlist (ping, nslookup, host, dig) to encode secrets from .env or /proc/PID/environ into DNS queries and exfiltrate them to an attacker-controlled server (CVE-2025-55284).

System

Framework
Claude Code (CLI)
Tools
bash, dns, filesystem
Vendor
Anthropic
Autonomy
supervised-autonomous

Classification

Primary class
prompt-injection
Chain
prompt-injection/indirect → data-exfiltration/via-tool
Attack vector
untrusted-content
Causation
entity: human · intentionality: intentional · timing: post-deployment

Trigger

Text in a file that Claude Code analyzed contained injected instructions. Because ping, nslookup, host, and dig were on the allowlist of commands that ran without user approval, the injection could read data from a .env file (or /proc/PID/environ), encode it into a hostname, and issue a command such as a ping — generating a DNS lookup that leaked the data to an external server.

Root cause

Network diagnostic commands were allowlisted to run without approval, and the agent acted on instructions from untrusted file content. Allowlisted commands that can trigger outbound DNS became a covert exfiltration channel that bypassed the normal Bash-tool authorization flow.

Contributing factors

  • Commands capable of outbound network activity (ping/nslookup/host/dig) were on the no-approval allowlist.
  • The agent treated instructions in analyzed file content as actionable.
  • Local secrets (.env, /proc/PID/environ) were reachable by the agent's tools.

Detection

Discovered and disclosed by researcher Johann Rehberger (wunderwuzzi); reported to Anthropic on 2025-05-26.

Recovery

Anthropic fixed the issue in Claude Code v1.0.4, released 2025-06-06; users were advised to upgrade.

Prevention

Keep commands that can cause outbound network requests off no-approval allowlists; treat file/tool content as untrusted; restrict egress and DNS from agent tool sandboxes; scope access to secrets; require approval for actions that can transmit data externally.

Blast radius

Data
API keys and environment variables (via .env files and /proc/PID/environ) could be encoded into DNS queries and exfiltrated to an attacker-controlled server. credentials
User harm
A disclosed vulnerability with a released fix; no confirmed in-the-wild exploitation was reported. none-reported
Scope
Claude Code CLI users before v1.0.4
Reversibility
reversible

References

CWE
CWE-200
OWASP LLM
LLM01 LLM02
MITRE ATLAS
AML.T0024 AML.T0051
Tags
prompt-injection data-exfiltration dns claude-code allowlist cve

Sources

Cite this incident

@misc{2025-claude-code-dns-exfiltration,
  title = {Claude Code could be prompt-injected into leaking secrets over DNS via allowlisted commands (CVE-2025-55284)},
  year = {2025},
  howpublished = {agent-postmortems},
  url = {https://swarmproof.github.io/agent-postmortems/2025-claude-code-dns-exfiltration/}
}