A chat assistant was steered into searching a user's own history and uploading it through an allowed endpoint
Oasis Security disclosed in March 2026 that an invisible instruction delivered in a URL parameter, combined with an open redirect and the code sandbox's allowed outbound endpoint, let an attacker make a default assistant session search the user's conversation history, write it to a file and upload it to the attacker's own account. No connectors or tools were needed.
The verdict
Verified
The document exists. The ledger fetched it at its publisher and quotes it.
Key facts
What the sources say
- Record ID
- AIL-2026-0017
- Kind
- Exfiltration
- Jurisdiction
- United States
- Last verified
- Added
- The research states that the code execution sandbox restricts outbound network access but allows connections to the vendor's own interface endpoint.
- The chain used an invisible injection carried in a URL query parameter, an open redirect on a vendor domain, and that allowed endpoint.
- The assistant searched the user's past conversations, wrote findings to a file and uploaded the file to an account the attacker controlled.
- No connectors, tools or extensions were required, so the attack worked against a default configuration.
- The vendor fixed the injection and the research states remaining items were being addressed at publication.
Dimension by dimension
6 dimensions, each one stated, silent or open
Identity, Authorization, Limits, Human approval, Revocation, Accountability. Stated means the document you can open below says it; silent means the ledger read the document and it does not.
- IdentitySilent
- Instructions arriving in a link ran with the standing of the signed in user.Oasis Security, prompt injection and data exfiltration in a chat assistant, primary source, 18 March 2026.
- AuthorizationSilent
- The session could read the user's entire conversation history with nothing narrowing it to the task at hand.Oasis Security, prompt injection and data exfiltration in a chat assistant, primary source, 18 March 2026.
- LimitsStated
- The sandbox egress allowlist did block arbitrary outbound network access, which is why the theft had to be routed through one allowed endpoint the vendor can see and close.Oasis Security, prompt injection and data exfiltration in a chat assistant, primary source, 18 March 2026.
- Human approvalSilent
- Writing the file and uploading it needed no confirmation from the user.Oasis Security, prompt injection and data exfiltration in a chat assistant, primary source, 18 March 2026.
- RevocationStated
- The vendor fixed the injection path after coordinated disclosure.Oasis Security, prompt injection and data exfiltration in a chat assistant, primary source, 18 March 2026.
- AccountabilityStated
- Named researchers, a coordinated timeline and named vendor fixes.Oasis Security, prompt injection and data exfiltration in a chat assistant, primary source, 18 March 2026.
What it changes
For a team deploying an agent
Note what the egress limit bought: the attacker could not reach an arbitrary server, so the theft had to cross an endpoint the vendor controls and monitors. That is what a limit is worth when injection succeeds anyway. Apply the same shape yourself: a strict outbound allowlist around anything that executes code for an agent, and no long conversation history in reach of a session opened from a link.
Sources
What this record was verified against
- Oasis Security, prompt injection and data exfiltration in a chat assistantPrimary · 18 March 2026
Related
Records that sit beside this one
ShadowLeak, a research agent that exfiltrated mailbox data from inside the vendor's own cloud
United States · verified 15 September 2026
Radware states that the deep research agent, executing in the vendor's cloud, performed the sensitive data exfiltration autonomously from those servers.
ClawJacked, where any website a user visited could pair itself with their local agent and drive it
Global · verified 15 September 2026
Oasis Security states that once paired, the attacker has full control and can interact with the agent, dump configuration data, enumerate connected devices and read logs.
A support agent invented a policy its company did not have, and customers cancelled over it
United States · verified 15 September 2026
A company representative stated publicly that there is no such policy and that users are free to use the product on multiple machines.
A vendor's own red team made a browser agent send a resignation letter for the user, then showed the fixed agent refusing
United States · verified 15 September 2026
The vendor's own account states that the out of office reply never gets written and the agent resigns on behalf of the user instead.
A browser agent read the local file system and shipped it out while still answering the user normally
United States · verified 15 September 2026
The research states the agent autonomously accesses the local file system and exfiltrates the contents to an attacker controlled endpoint while still returning the expected response.
GitLost, where a platform's own workflow agent posted private repository contents into a public issue when asked politely
United States · verified 15 September 2026
The Register reports that the attacker hides the commands in plain English in the issue body and the agent then posts the data as a public comment.
Cite this record
Free to reuse under CC BY 4.0, with attribution. The record ID AIL-2026-0017 is permanent and is never reused.
- In a sentence
- According to the GAGE Agent Incident Ledger (as of 15 September 2026), a chat assistant was steered into searching a user's own history and uploading it through an allowed endpoint.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). A chat assistant was steered into searching a user's own history and uploading it through an allowed endpoint. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0017-claude-ai-chat-history-exfiltrated-through-allowed-endpoint
- MLA
- "A chat assistant was steered into searching a user's own history and uploading it through an allowed endpoint." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0017-claude-ai-chat-history-exfiltrated-through-allowed-endpoint.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "A chat assistant was steered into searching a user's own history and uploading it through an allowed endpoint." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0017-claude-ai-chat-history-exfiltrated-through-allowed-endpoint.
- Permalink
- https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0017-claude-ai-chat-history-exfiltrated-through-allowed-endpoint
Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.
Back to the full ledger, or every record for United States and every exfiltration record.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.