Claude Code Router Cross-Origin Resource Sharing Misconfiguration Vulnerability

Vulnerability

A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability has been identified in Claude Code Router versions prior to 1.0.34. This vulnerability exposes user API keys or equivalent credentials to untrusted domains. Attackers could exploit this issue to steal credentials, misuse accounts, deplete quotas, or access sensitive information.

Impact

Exploitation of this vulnerability could lead to the exposure of user API keys or equivalent credentials, allowing attackers to steal credentials, abuse accounts, exhaust quotas, or access sensitive data.

Remediation

Users can upgrade to Claude Code Router version 1.0.34 or later to address this vulnerability.

Added: Aug 21, 2025, 5:28 PM
Updated: Aug 21, 2025, 5:28 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
7.4
remediation
7.7
relevance
0.4
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.