Researchers disclosed PromptFiction, a vulnerability in Anthropic’s Claude Desktop app that let a crafted claude:// link automatically open the application and submit an attacker-controlled prompt without requiring the user to review or press send. Oasis Security reported the issue through Anthropic’s responsible disclosure program, and Anthropic patched the behavior in Claude Desktop version 1.1.2321 so prompts delivered through the custom URI scheme are only pre-filled for manual review before submission.
The flaw could be delivered through websites, documents, emails, chat messages, or search results, and researchers said attackers could hide malicious instructions using benign padding and Claude’s message-folding behavior. On its own, the bug enabled reliable prompt injection and possible exfiltration of prior conversation data or abuse of connected tools; when chained with previously disclosed Claudy Day issues and environments using Anthropic’s official Filesystem Server, it could allow local file read/write access, persistence, malicious code planting, and ultimately remote code execution on the victim machine.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
Anthropic remediated the PromptFiction issue by changing Claude Desktop so prompts delivered via the claude:// scheme are only pre-filled and must be manually reviewed and sent. The fix was released in Claude Desktop version 1.1.2321.
Oasis Security identified the PromptFiction vulnerability in Anthropic's Claude Desktop and reported it through Anthropic's responsible disclosure program. The flaw allowed a crafted claude:// link to automatically submit attacker-controlled prompts without user review or confirmation.
Researchers publicly disclosed PromptFiction as a Claude Desktop vulnerability that enabled one-click prompt injection via the app's custom URI handler. They also described how chaining it with previously disclosed Claudy Day flaws could enable data exfiltration, local file access, persistence, and possible remote code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
hackread.com
Open sourcedarkreading.com
Open sourceoasis.security
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.