Claude Cowork Exfiltrates Files
Read OriginalA security researcher discovered a vulnerability in Claude Cowork where its default HTTP allowlist, designed to prevent data exfiltration, could be bypassed. The attack used the permitted Anthropic API domain with an attacker's API key to upload files from the agent to the API endpoint, enabling data theft.
Comments
No comments yet
Be the first to share your thoughts!
Browser Extension
Get instant access to AllDevBlogs from your browser