Anthropic's 'Cowork' Vulnerable to File Exfiltration via Indirect Prompt Injection
Analysis
Key Takeaways
- •Anthropic's 'Cowork' AI agent is vulnerable to indirect prompt injection.
- •The vulnerability allows for the execution of malicious prompts from user-uploaded files.
- •This vulnerability could lead to file exfiltration.
“Anthropic's 'Cowork' has a vulnerability that allows it to read and execute malicious prompts from files uploaded by the user.”