One-click Claude Desktop flaw could enable hidden prompt injection and code execution
28 July 2026 at 07:12
Security researchers at Oasis Security have disclosed a vulnerability in Claude Desktop that could allow attackers to execute hidden prompts, access local files, exfiltrate conversation history, or execute code with a single click on a malicious link. The vulnerability, dubbed PromptFiction, affects the way Claude Desktop handled claude:// links.ย According to the researchers, clicking one [...]