Skip to main content
← Back to sources

Claude web_fetch Exfiltration Flaw — Nested-Link Attack Leaks User Memory

Published 2026-07-15AI Engineering PracticesHigh

Summary

Security researcher Ayush Paul disclosed a data-exfiltration vulnerability in Claude's `web_fetch` tool, published on Simon Willison's weblog on July 15, 2026. The tool was designed to resist direct URL manipulation by only navigating to user-entered URLs or links returned by search — but Paul found `web_fetch` would also follow links embedded inside pages it had already fetched. An attacker could stand up a honeypot page presenting a fake "authentication" prompt that instructed Claude to walk a

Alignment: Reinforces current position
Related Positions: AI Governance and Risk, Agentic Workflows, AI-Assisted Development Tooling
Related Partnerships: Anthropic (Claude)
security-disclosureprompt-injectiondata-exfiltrationagentic-toolingclaudeweb-fetchagent-memoryai-governance