Claude Vulnerabilities Allow Data Exfiltration and User Redirection to Malicious Sites
ID: 1885d8dd-1a57-5910-9290-50ca5f69daf5
STIX ID: report--1885d8dd-1a57-5910-9290-50ca5f69daf5
Feed Name: cybersecurityNews.com
**Executive Summary:** Researchers disclosed a chained vulnerability in Claude.ai — an invisible prompt injection delivered via pre-filled URL parameters, abuse of the Anthropic Files API to silently upload extracted conversation data to an attacker-controlled Anthropic account, and an open redirect on claude.com that can be weaponized to deliver the exploit (e.g., through ads). The primary prompt injection was patched after responsible disclosure; remaining issues are being addressed. Organizations should audit agent integrations, restrict permissions, and apply access controls and audit trails to AI agents.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
