Claude web_fetch Exfiltration Flaw — Nested-Link Attack Leaks User Memory
Published 2026-07-15AI Engineering PracticesHigh
Summary
Security researcher Ayush Paul disclosed a data-exfiltration vulnerability in Claude's `web_fetch` tool, published on Simon Willison's weblog on July 15, 2026. The tool was designed to resist direct URL manipulation by only navigating to user-entered URLs or links returned by search — but Paul found `web_fetch` would also follow links embedded inside pages it had already fetched. An attacker could stand up a honeypot page presenting a fake "authentication" prompt that instructed Claude to walk a
Alignment: Reinforces current position
Related Positions: AI Governance and Risk, Agentic Workflows, AI-Assisted Development Tooling
Related Partnerships: Anthropic (Claude)
security-disclosureprompt-injectiondata-exfiltrationagentic-toolingclaudeweb-fetchagent-memoryai-governance