Low severityOSV Advisory· Published Dec 4, 2025· Updated Apr 15, 2026
CVE-2025-66479
CVE-2025-66479
Description
Anthropic Sandbox Runtime is a lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container. Prior to 0.0.16, due to a bug in sandboxing logic, sandbox-runtime did not properly enforce a network sandbox if the sandbox policy did not configure any allowed domains. This could allow sandboxed code to make network requests outside of the sandbox. A patch for this was released in v0.0.16.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@anthropic-ai/sandbox-runtimenpm | < 0.0.16 | 0.0.16 |
Affected products
2Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-9gqj-5w7c-vx47ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-66479ghsaADVISORY
- github.com/anthropic-experimental/sandbox-runtime/commit/bea2930cc1db9c73a1b15acf6dc19c5261aec1f3nvdWEB
- github.com/anthropic-experimental/sandbox-runtime/security/advisories/GHSA-9gqj-5w7c-vx47nvdWEB
News mentions
2- Even Claude agrees: hole in its sandbox was real and dangerousThe Register Security · May 20, 2026
- Anthropic Silently Patches Claude Code Sandbox BypassSecurityWeek · May 20, 2026