VBS-2026-0009CRITICALCVSS 9.4CWE-601

Claude Claudy Day chain: URL prompt injection + open redirect + chat exfiltration

A reported multi-step chain combined URL-based hidden prompt injection, redirect trust abuse, and an allowed upload/exfil path to extract Claude chat history in default-session workflows.

Published
2026-03-18
Discovered By
Oasis Security
CVSS Score
9.4 / 10
Affected AI Platforms
Claude
Affected Tech Stack
Chat prefill URLsRedirect handlersAssistant file upload flows
Remediation

Treat URL-prefill content as untrusted input, block or sign redirect targets, and require explicit high-friction consent for assistant-initiated uploads or exfil-prone actions.

#claude#prompt-injection#open-redirect#data-exfiltration#chain
Check if your app is vulnerable to VBS-2026-0009

PolyDefender detects this and dozens of other AI-specific vulnerability patterns.

FAQ
Q

How do I check if my Chat prefill URLs + Redirect handlers app is affected by claude Claudy Day chain: URL prompt injection + open redirect + chat exfiltration?

A

A reported multi-step chain combined URL-based hidden prompt injection, redirect trust abuse, and an allowed upload/exfil path to extract Claude chat history in default-session workflows.. Search your codebase for Chat prefill URLs, Redirect handlers, Assistant file upload flows patterns and verify the remediation has been applied. This is rated CVSS 9.4 — treat it as a live incident if your app is already in production.

Q

Why does Claude generate code with CWE-601 (critical severity)?

A

A reported multi-step chain combined URL-based hidden prompt injection, redirect trust abuse, and an allowed upload/exfil path to extract Claude chat history in default-session workflows.

Q

How do I fix claude Claudy Day chain: URL prompt injection + open redirect + chat exfiltration?

A

Treat URL-prefill content as untrusted input, block or sign redirect targets, and require explicit high-friction consent for assistant-initiated uploads or exfil-prone actions.

Q

What can an attacker do if my app contains VBS-2026-0009?

A

With CVSS 9.4 (critical), this vulnerability is critical — an attacker can likely gain complete control of your data or infrastructure.