claude-code-router is a powerful tool to route Claude Code requests to different models and customize any request. Due to improper Cross-Origin Resource Sharing (CORS) configuration, there is a risk that user API Keys or equivalent credentials may be exposed to untrusted domains. Attackers could exploit this misconfiguration to steal credentials, abuse accounts, exhaust quotas, or access sensitive data. The issue has been patched in v1.0.34.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-25479 | @musistudio/claude-code-router has improper CORS configuration |
Github GHSA |
GHSA-8hmm-4crw-vm2c | @musistudio/claude-code-router has improper CORS configuration |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 21 Aug 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 21 Aug 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | claude-code-router is a powerful tool to route Claude Code requests to different models and customize any request. Due to improper Cross-Origin Resource Sharing (CORS) configuration, there is a risk that user API Keys or equivalent credentials may be exposed to untrusted domains. Attackers could exploit this misconfiguration to steal credentials, abuse accounts, exhaust quotas, or access sensitive data. The issue has been patched in v1.0.34. | |
| Title | claude-code-router CORS. misconfiguration | |
| Weaknesses | CWE-200 CWE-942 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-08-21T17:31:44.119Z
Reserved: 2025-08-19T15:16:22.916Z
Link: CVE-2025-57755
Updated: 2025-08-21T17:23:17.717Z
Status : Awaiting Analysis
Published: 2025-08-21T17:15:31.610
Modified: 2025-08-22T18:08:51.663
Link: CVE-2025-57755
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA