A new vulnerability in Anthropic’s Claude Desktop AI assistant has been discovered, allowing attackers to automatically submit malicious prompts with just a single click. The flaw, dubbed “PromptFiction,” was found by researchers at Oasis Security and could have enabled an end-to-end attack on targeted systems, including the exfiltration of user conversations and even remote code execution.
The vulnerability works by exploiting Claude Desktop’s registration of a custom URI scheme, “claude://.” When a user clicks on a crafted “claude://” link, it automatically opens the desktop application and submits a prepared prompt to the AI agent. This means that there is no opportunity for the user to review or interact with the malicious prompt before it is executed.
This type of attack is known as a prompt injection vulnerability, where an attacker injects malicious instructions into the AI agent without requiring user input. In this case, the PromptFiction flaw takes it to the next level by eliminating the need for a user to hit the Enter or Send button to submit the malicious prompt. The researchers at Oasis Security demonstrated that a single click on a link in a browser, chat message, document, or search result was enough to put attacker-authored instructions in front of the AI agent and have them executed.
The combination of PromptFiction with another exploit, dubbed “Claudy Day,” could have enabled an end-to-end attack on targeted systems. Claudy Day demonstrated a different form of prompt injection where an invisible prompt could be smuggled into a claude.ai chat through a pre-filled URL that still required the user pressing Enter to send the prompt to the AI assistant.
Fortunately, Anthropic has already fixed the PromptFiction flaw in version 1.1.2321 of Claude Desktop, and users are advised to ensure they are running this release or later to prevent any potential attacks. The responsible disclosure of the vulnerability and its rapid remediation is seen as a positive outcome by experts in the field.
However, the existence of the PromptFiction flaw highlights the increasing pace at which security vulnerabilities are being discovered and exploited in emerging technologies like AI. As Randolph Barr, chief information security officer at Cequence Security, notes, “The same models that help defenders are helping attackers find and weaponize flaws faster.” This means that organizations must adapt to the rapid pace of AI and use AI tools themselves to review and secure what they ship as fast as they ship it.
In practical terms, this means that users of AI assistants like Claude Desktop should be cautious when clicking on links or interacting with suspicious prompts. Additionally, developers and researchers working with AI agents should prioritize responsible disclosure and remediation of security vulnerabilities to prevent potential attacks. By staying vigilant and adapting to the rapidly evolving threat landscape, we can better secure our systems against the next level of prompt injection attacks made possible by AI agents.
Source: Dark Reading — 2026-07-15