AI Agent Can Access File Upload API to Exfiltrate DocumentsSecurity researchers have demonstrated how Anthropic’s new Claude Cowork productivity agent can be tricked into stealing user files and uploading them to an attacker’s account, exploiting a vulnerability the company allegedly knew about.

  • leds@feddit.dk
    link
    fedilink
    English
    arrow-up
    1
    ·
    2 months ago

    But this is uploading the data to same api it uses in the first place, just uploads it to someone else’s account.