PromptFiction Flaw Auto-Submitted Hidden Prompts in Claude Desktop

https://hackread.com/wp-content/uploads/2026/07/promptfiction-flaw-auto-prompts-claude-desktop.jpg

A single click on a crafted link could cause Claude Desktop to execute attacker-written instructions without prompting the user to review or send the prompt, according to new research from Oasis Security.

Securityaudit services

The vulnerability, named PromptFiction, affected Anthropic’s Claude Desktop application and used its custom claude:// URL scheme.

For context, a malicious link could open the app, submit a prepared prompt automatically, and instruct the AI agent to access sensitive information or perform actions through connected tools.

Anthropic fixed the flaw after it was reported through the company’s Responsible Disclosure Program.

However, before the correction, clicking a crafted link was enough to submit the prompt, with no confirmation screen or opportunity to inspect the instructions before Claude processed them.

Discover more

Machine Learning & Artificial Intelligence

Network security solutions

Engineering & Technology

Claude Desktop registers itself as a handler...

Copyright of this story solely belongs to hackread.com. To see the full text click HERE

Read more