logo

Claude Flaw Automatically Sends Malicious Prompts to AI Agents

ID: 85f804a3-3625-5034-88d7-c3ad4c8dce53

STIX ID: report--85f804a3-3625-5034-88d7-c3ad4c8dce53

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2026-07-15

Date Updated: 2026-07-16

Author: Elizabeth Montalbano

...
...

Anthropic's Claude Desktop had a flaw named "PromptFiction" where a crafted claude:// link could open the app and automatically submit a hidden, attacker-crafted prompt without user review; combined with previously disclosed "Claudy Day" issues this chain could lead to data exfiltration, local file access, persistence and possible remote code execution. Oasis Security reported the issue and Anthropic patched it in Claude Desktop version 1.1.2321; organizations are advised to update and apply governance and monitoring controls for AI agents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.