• News/
  • darkreading-20260715152735

Claude Flaw Automatically Sends Malicious Prompts to AI Agents

Dark Reading
·
Elizabeth Montalbano
·
Published Jul 15, 2026
·
Updated

A vulnerability in Anthropic's Claude Desktop application could have allowed attackers to automatically submit malicious prompts to the AI assistant with a single click and without any interaction from a user at all. Anthropic already has fixed the flaw, but it demonstrates the next level of prompt injection attacks that are possible using AI agents. Researchers from Oasis Security discovered the flaw, dubbed "PromptFiction," which — when combined with a previous trio of flaws they found in Claude, dubbed "Claudy Day" — could have enabled an end-to-end attack on the targeted system, according to a report published Wednesday. This would facilitate "silent exfiltration of the user's previous conversations and, when Anthropic's official Filesystem Server is installed, read/write access to local files, persistence, and ultimately remote code execution on the victim's machine," Elad Luz, research lead at Oasis, wrote in the report. PromptFiction demonstrates a prompt injection attack that doesn't require a key aspect of previous examples of this class of threats within an AI agent — a user hitting the Enter or Send button to submit a malicious prompt unknowingly. What Oasis found is that Claude Desktop registers a custom URI scheme, "claude://," and that a crafted "claude://" link automatically opens the desktop application and submits a prepared prompt to the agent. This eliminates the "send" action and thus there is "no opportunity for the user to review it," according to the re...

Read full article

Affected Software

1 affected component
Anthropic Claude Desktop<1.1.2321
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a security vulnerability in Anthropic's Claude Desktop application that allowed attackers to submit malicious prompts automatically.

2

What security implications are discussed in the article?

The article highlights the risk of automated exploitation of AI applications, leading to potential misuse without user interaction.

3

What products or software are affected by this vulnerability?

The affected software is the Anthropic Claude Desktop application.

4

How was the vulnerability in Claude Desktop addressed?

Anthropic has fixed the vulnerability, mitigating the risk of automatic prompt submission by attackers.

5

When was the vulnerability reported and fixed?

The vulnerability was published on July 15, 2026, and was exploited on July 16, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203