Executive brief
@musistudio/claude-code-router is a Node.js library that provides routing capabilities for Claude code interactions. Due to improper CORS (Cross-Origin Resource Sharing) configuration, user API keys and credentials can be exposed to untrusted domains, allowing attackers to steal credentials, abuse accounts, or access sensitive data.
Technical details
The vulnerability stems from improper CORS configuration (CWE-200, CWE-942) in @musistudio/claude-code-router that allows credentials such as API keys to be exposed to untrusted domains. The misconfiguration likely permits overly broad origin allowances, enabling cross-origin requests from arbitrary sites to access sensitive authentication tokens. An attacker can exploit this by hosting a malicious website that sends requests to a vulnerable instance of the router; if a user visits the attacker's site while authenticated, the browser will include credentials in the cross-origin request. This exposure allows attackers to steal API keys, abuse user accounts, exhaust service quotas, or access sensitive data. The issue is patched in version 1.0.34.
Affected products
- musistudio claude-code-router before 1.0.34
Timeline
- 2025-08-21: disclosed
- 2025-08-21: patched: v1.0.34