Anthropic's 'Cowork' Vulnerable to File Exfiltration via Indirect Prompt Injection

safety#agent📝 Blog|Analyzed: Jan 15, 2026 12:00
Published: Jan 15, 2026 12:00
1 min read
Gigazine

Analysis

This vulnerability highlights a critical security concern for AI agents that process user-uploaded files. The ability to inject malicious prompts through data uploaded to the system underscores the need for robust input validation and sanitization techniques within AI application development to prevent data breaches.
Reference / Citation
View Original
"Anthropic's 'Cowork' has a vulnerability that allows it to read and execute malicious prompts from files uploaded by the user."
G
GigazineJan 15, 2026 12:00
* Cited for critical analysis under Article 32.