logo

Claude Vulnerabilities Allow Data Exfiltration and User Redirection to Malicious Sites

ID: 1885d8dd-1a57-5910-9290-50ca5f69daf5

STIX ID: report--1885d8dd-1a57-5910-9290-50ca5f69daf5

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-03-19

Date Updated: 2026-04-21

Author: Abinaya

...
...

**Executive Summary:** Researchers disclosed a chained vulnerability in Claude.ai — an invisible prompt injection delivered via pre-filled URL parameters, abuse of the Anthropic Files API to silently upload extracted conversation data to an attacker-controlled Anthropic account, and an open redirect on claude.com that can be weaponized to deliver the exploit (e.g., through ads). The primary prompt injection was patched after responsible disclosure; remaining issues are being addressed. Organizations should audit agent integrations, restrict permissions, and apply access controls and audit trails to AI agents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.