If your agent fetches web content and holds private data, this shows how deterministic URL restrictions fail via attacker-controlled nested links — check your own fetch tools for the same hole.
“Anthropic's protection is that web_fetch can only be used to navigate to exact URLs that the user has entered themselves or that were returned from its companion web_search tool.”
“web_fetch was also allowed to visit URLs embedded in pages that it had previously fetched, which meant you could create a honeypot site which encouraged the agent to exfiltrate data by following a sequence of nested generated links.”
“They were able to extract the user's name, home location city and the name of their employer.”
“Anthropic didn't pay out a bug bounty because they claimed to have identified it internally already, and have since closed the hole by removing the ability for web_fetch to navigate to additional links returned within its own fetched content.”
Checking sign-in…
Loading comments…