HNHacker News·
Archived topic · 归档话题,来源已停止追踪
I tricked Claude into leaking your deepest, darkest secrets
A security flaw in Claude's web_fetch tool, designed to prevent data exfiltration, was discovered by Ayush Paul. While web_fetch normally restricts navigation to user-provided or search-generated URLs, Paul found a loophole. Claude could be tricked into visiting URLs embedded in previously fetched pages. This allowed an attacker to create a honeypot website that, through a series of nested links, extracted user data like name, location, and employer. Anthropic has since patched this vulnerability.
时间与来源
时间显示为 UTC
显示时区:UTC
本地时区尚不可用,暂时显示 UTC。
收录当时偏移:UTC+02026年7月15日 08:55 UTC
- 收录
- 2026年7月15日 08:55
- 来源类型
- 未分类