claude-code-router is a powerful tool to route Claude Code requests to different models and customize any request. Due to improper Cross-Origin Resource Sharing (CORS) configuration, there is a risk that user API Keys or equivalent credentials may be exposed to untrusted domains. Attackers could exploit this misconfiguration to steal credentials, abuse accounts, exhaust quotas, or access sensitive data. The issue has been patched in v1.0.34.
Metrics
Affected Vendors & Products
References
History
Thu, 21 Aug 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 21 Aug 2025 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | claude-code-router is a powerful tool to route Claude Code requests to different models and customize any request. Due to improper Cross-Origin Resource Sharing (CORS) configuration, there is a risk that user API Keys or equivalent credentials may be exposed to untrusted domains. Attackers could exploit this misconfiguration to steal credentials, abuse accounts, exhaust quotas, or access sensitive data. The issue has been patched in v1.0.34. | |
Title | claude-code-router CORS. misconfiguration | |
Weaknesses | CWE-200 CWE-942 |
|
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-08-21T16:21:33.485Z
Updated: 2025-08-21T17:31:44.119Z
Reserved: 2025-08-19T15:16:22.916Z
Link: CVE-2025-57755

Updated: 2025-08-21T17:23:17.717Z

Status : Awaiting Analysis
Published: 2025-08-21T17:15:31.610
Modified: 2025-08-22T18:08:51.663
Link: CVE-2025-57755

No data.