Claude Flaw Automatically Sends Malicious Prompts to AI Agents
ID: 85f804a3-3625-5034-88d7-c3ad4c8dce53
STIX ID: report--85f804a3-3625-5034-88d7-c3ad4c8dce53
Feed Name: Dark Reading
Anthropic's Claude Desktop had a flaw named "PromptFiction" where a crafted claude:// link could open the app and automatically submit a hidden, attacker-crafted prompt without user review; combined with previously disclosed "Claudy Day" issues this chain could lead to data exfiltration, local file access, persistence and possible remote code execution. Oasis Security reported the issue and Anthropic patched it in Claude Desktop version 1.1.2321; organizations are advised to update and apply governance and monitoring controls for AI agents.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
