A novel indirect prompt injection attack allows threat actors to compromise Anthropic's Claude AI Code Interpreter, leveraging its network features to exfiltrate sensitive user chat data. This exploit bypasses default network settings by tricking Claude into uploading sandbox-stored user information directly to an attacker's account via Anthropic's own APIs.
Why This Matters
Publisher reporting describes a security event affecting Claude. BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.
Recommended Action
Confirm whether Claude is present in your environment and review vendor guidance for this report. Apply available patches or mitigations if your deployment matches the described conditions.
Affected