Claude Flaw Automatically Sends Malicious Prompts to AI Agents

A newly discovered vulnerability in Anthropic’s Claude Desktop AI assistant has revealed a concerning level of sophistication in prompt injection attacks. The flaw, dubbed “PromptFiction,” could have allowed attackers to submit malicious prompts to the AI agent with just one click, without requiring any user interaction. While Anthropic has already fixed the issue, the discovery highlights the evolving threat landscape and the increasing pace at which security vulnerabilities are being discovered and exploited.

Researchers from Oasis Security identified PromptFiction as a way for attackers to bypass traditional prompt injection attacks, which typically require a user to submit a malicious prompt by pressing Enter or Send. Instead, the vulnerability allows a crafted “claude://” link to automatically open the Claude Desktop application and submit a prepared prompt to the AI agent, eliminating the need for user review.

This type of attack is particularly concerning because it can be delivered through various mediums, including websites, documents, chat messages, emails, or search results. A single click on such a malicious link could put attacker-authored instructions in front of the AI agent, allowing them to be executed without any further action required from the user.

The discovery of PromptFiction is not an isolated incident. Researchers at Oasis also identified a previous trio of flaws in Claude, dubbed “Claudy Day,” which demonstrated a different form of prompt injection attack. While Anthropic has since fixed these issues, the existence of such vulnerabilities highlights the importance of staying vigilant and adapting to the rapid pace of emerging technology.

Experts warn that the increasing speed at which security gaps are discovered and exploited is due in part to the use of AI tools by both defenders and attackers. As AI models become more sophisticated, they are helping researchers discover and weaponize flaws faster than ever before. This has created a window of vulnerability between when a flaw exists and when a patch is shipped.

To mitigate this risk, experts recommend turning the same AI tools back onto the problem to review and secure what is being shipped as fast as it is released. This approach acknowledges that traditional methods of reviewing every release may no longer be effective in today’s rapid-paced environment.

In summary, the discovery of PromptFiction serves as a stark reminder of the evolving threat landscape and the need for increased vigilance in securing AI agents and emerging technology. While Anthropic has fixed the issue, it is essential to recognize that such vulnerabilities can have significant consequences if left unaddressed. By adapting to the rapid pace of AI and embracing proactive security measures, organizations can better protect themselves against the growing threat of prompt injection attacks.


Source: Dark Reading — 2026-07-15