Claude Relay Service (CRS): Open-Source Solution for Unified AI API Access and Cost Sharing, Addressing Critical Security Vulnerability
The Claude Relay Service (CRS) is an open-source relay service designed to unify access to various AI models, including Claude, OpenAI, Gemini, and Droid subscriptions. It enables users to build their own Claude Code mirror, facilitating seamless integration with native tools and supporting 'carpooling' for more efficient cost sharing. A critical security update has been issued, warning users of versions v1.1.248 and below about a severe administrator authentication bypass vulnerability, which allows unauthorized access to the management panel.
The Claude Relay Service (CRS) offers a comprehensive open-source relay solution for managing access to multiple artificial intelligence platforms. This service allows users to establish their own Claude Code mirror, providing a unified access point for various AI subscriptions, including Claude, OpenAI, Gemini, and Droid. A key feature of CRS is its support for 'carpooling' or shared access, which helps in more efficiently distributing and reducing operational costs among users. The service is designed to ensure seamless integration and use with native tools.
However, a significant security alert has been issued regarding the Claude Relay Service. Versions v1.1.248 and earlier are affected by a critical administrator authentication bypass vulnerability. This flaw allows unauthorized individuals to gain access to the management panel, posing a serious security risk. Users are strongly advised to update their installations to a patched version to mitigate this vulnerability and protect their systems from potential attacks.