|
Claude · Security Report
|
CONFIDENTIAL |
|
|
Scan Summary · 2026-05-24
Vulnerability findings for claude.ai
https://claude.ai/ · 160.79.104.10
|
|
The latest scan identified 101 findings across the public-facing infrastructure. Critical: 0, High: 1 — review urgently. Low: 11, Informational: 85.
|
|
Critical
0
|
High
1
|
Medium
4
|
Low
11
|
Info
85
|
|
|
REPORT 12b67402
|
SCAN 23:33 UTC
|
TOOLS httpx · nmap · subfinder · zap
|
|
|
|
| H-01 |
PII Disclosure
— · 2 instance(s)
|
High
|
|
| Medium severity |
4 FINDINGS |
|
|
| M-01 |
CSP: Wildcard Directive
— · 5 instance(s)
|
Medium
|
|
| M-02 |
CSP: style-src unsafe-inline
— · 5 instance(s)
|
Medium
|
|
| M-03 |
Source Code Disclosure - SQL
— · 2 instance(s)
|
Medium
|
|
| M-04 |
Sub Resource Integrity Attribute Missing
— · 5 instance(s)
|
Medium
|
|
|
|
| L-01 |
Cookie No HttpOnly Flag
— · 5 instance(s)
|
Low
|
|
| L-02 |
Cookie with SameSite Attribute None
— · 5 instance(s)
|
Low
|
|
| L-03 |
Cookie without SameSite Attribute
— · 3 instance(s)
|
Low
|
|
| L-04 |
Cross-Domain JavaScript Source File Inclusion
— · 5 instance(s)
|
Low
|
|
| L-05 |
Cross-Origin-Embedder-Policy Header Missing or Invalid
— · 5 instance(s)
|
Low
|
|
| L-06 |
Cross-Origin-Opener-Policy Header Missing or Invalid
— · 5 instance(s)
|
Low
|
|
| L-07 |
Private IP Disclosure
— · 12 instance(s)
|
Low
|
|
| L-08 |
Server Leaks Information via "X-Powered-By" HTTP Response Header Field(s)
— · 5 instance(s)
|
Low
|
|
| L-09 |
Strict-Transport-Security Header Not Set
— · 5 instance(s)
|
Low
|
|
| L-10 |
Timestamp Disclosure - Unix
— · 5 instance(s)
|
Low
|
|
| L-11 |
X-Content-Type-Options Header Missing
— · 5 instance(s)
|
Low
|
|
| Informational |
85 FINDINGS |
|
| 4 network observation(s) on 160.79.104.10: http/80, https/443, http-proxy/8080, https-alt/8443 plus httpx (1) plus subfinder (74). |
|
|
The detailed HTML report (full_vulnerable_reports) lists evidence, endpoints, and remediation text where the scanner provided it.
|
This message contains confidential security information. Do not forward outside the intended recipient list. |
REPORT 12b67402 2026-05-24 |
|