Claude · Security Report CONFIDENTIAL
Scan Summary · 2026-05-24

Vulnerability findings for claude.ai

https://claude.ai/  ·  160.79.104.10

The latest scan identified 101 findings across the public-facing infrastructure. Critical: 0, High: 1 — review urgently. Low: 11, Informational: 85.

Critical
0
High
1
Medium
4
Low
11
Info
85
REPORT  12b67402 SCAN  23:33 UTC TOOLS  httpx · nmap · subfinder · zap
High severity 1 FINDINGS
H-01
PII Disclosure
— · 2 instance(s)
High
Medium severity 4 FINDINGS
M-01
CSP: Wildcard Directive
— · 5 instance(s)
Medium
M-02
CSP: style-src unsafe-inline
— · 5 instance(s)
Medium
M-03
Source Code Disclosure - SQL
— · 2 instance(s)
Medium
M-04
Sub Resource Integrity Attribute Missing
— · 5 instance(s)
Medium
Low severity 11 FINDINGS
L-01
Cookie No HttpOnly Flag
— · 5 instance(s)
Low
L-02
Cookie with SameSite Attribute None
— · 5 instance(s)
Low
L-03
Cookie without SameSite Attribute
— · 3 instance(s)
Low
L-04
Cross-Domain JavaScript Source File Inclusion
— · 5 instance(s)
Low
L-05
Cross-Origin-Embedder-Policy Header Missing or Invalid
— · 5 instance(s)
Low
L-06
Cross-Origin-Opener-Policy Header Missing or Invalid
— · 5 instance(s)
Low
L-07
Private IP Disclosure
— · 12 instance(s)
Low
L-08
Server Leaks Information via "X-Powered-By" HTTP Response Header Field(s)
— · 5 instance(s)
Low
L-09
Strict-Transport-Security Header Not Set
— · 5 instance(s)
Low
L-10
Timestamp Disclosure - Unix
— · 5 instance(s)
Low
L-11
X-Content-Type-Options Header Missing
— · 5 instance(s)
Low
Informational 85 FINDINGS
4 network observation(s) on 160.79.104.10: http/80, https/443, http-proxy/8080, https-alt/8443 plus httpx (1) plus subfinder (74).

The detailed HTML report (full_vulnerable_reports) lists evidence, endpoints, and remediation text where the scanner provided it.

This message contains confidential security information.
Do not forward outside the intended recipient list.
REPORT 12b67402
2026-05-24

Claude · Automated security scan summary