Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

In the article it says that Cowork is running in a VM that has limited network availability, but the Anthropic endpoint is required. What they don't do is check that the API call you make is using the same API key as the one you created the Cowork session with.

So the prompt injection adds a "skill" that uses curl to send the file to the attacker via their API key and the file upload function.





Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: