logo

PromptFiction Flaw Auto-Submitted Hidden Prompts in Claude Desktop

ID: bbe91a0c-c50d-5449-8a9d-4f02d0fbccd8

STIX ID: report--bbe91a0c-c50d-5449-8a9d-4f02d0fbccd8

Feed Name: HackRead

Threat Score
70/100

Date Published: 2026-07-15

Date Updated: 2026-07-16

Author: Waqas

...
...

Oasis Security disclosed “PromptFiction,” a vulnerability in Anthropic’s Claude Desktop where the app’s claude:// URL handler accepted a q parameter and automatically submitted prompts when a user clicked crafted links. Attackers could hide malicious instructions in long prompts to exfiltrate previous conversations via the Files API, and—when filesystem integration was enabled—implant remote debugging code or persistence in user files, potentially enabling code execution. Anthropic fixed the behavior so prompts are pre-filled and require user review in Claude Desktop version 1.1.2321 or later.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.