Claude AI vulnerability exposes enterprise data through code interpreter exploit

Claude AI Vulnerability Exposes Enterprise Data

A newly disclosed vulnerability in Anthropic's Claude AI assistant has revealed how attackers can exploit the platform's code interpreter feature to exfiltrate enterprise data.

Security researcher Johann Rehberger demonstrated that Claude's code interpreter can be manipulated through indirect prompt injection to steal sensitive information, including:

The attack leveraged Claude's own API infrastructure to send stolen data directly to attacker-controlled accounts, bypassing default security settings.

The exploit took advantage of a critical oversight in Claude's network access controls.

Author's summary: Claude AI vulnerability exposes data through code interpreter exploit.

more

CSO Online CSO Online — 2025-10-31

More News