Skip to main content
VerifiedExfiltration

A chat assistant was steered into searching a user's own history and uploading it through an allowed endpoint

Oasis Security disclosed in March 2026 that an invisible instruction delivered in a URL parameter, combined with an open redirect and the code sandbox's allowed outbound endpoint, let an attacker make a default assistant session search the user's conversation history, write it to a file and upload it to the attacker's own account. No connectors or tools were needed.

The verdict

Verified

The document exists. The ledger fetched it at its publisher and quotes it.

Key facts

What the sources say

Record ID
AIL-2026-0017
Kind
Exfiltration
Jurisdiction
United States
Last verified
Added
  • The research states that the code execution sandbox restricts outbound network access but allows connections to the vendor's own interface endpoint.
  • The chain used an invisible injection carried in a URL query parameter, an open redirect on a vendor domain, and that allowed endpoint.
  • The assistant searched the user's past conversations, wrote findings to a file and uploaded the file to an account the attacker controlled.
  • No connectors, tools or extensions were required, so the attack worked against a default configuration.
  • The vendor fixed the injection and the research states remaining items were being addressed at publication.

Dimension by dimension

6 dimensions, each one stated, silent or open

Identity, Authorization, Limits, Human approval, Revocation, Accountability. Stated means the document you can open below says it; silent means the ledger read the document and it does not.

IdentitySilent
Instructions arriving in a link ran with the standing of the signed in user.Oasis Security, prompt injection and data exfiltration in a chat assistant, primary source, 18 March 2026.
AuthorizationSilent
The session could read the user's entire conversation history with nothing narrowing it to the task at hand.Oasis Security, prompt injection and data exfiltration in a chat assistant, primary source, 18 March 2026.
LimitsStated
The sandbox egress allowlist did block arbitrary outbound network access, which is why the theft had to be routed through one allowed endpoint the vendor can see and close.Oasis Security, prompt injection and data exfiltration in a chat assistant, primary source, 18 March 2026.
Human approvalSilent
Writing the file and uploading it needed no confirmation from the user.Oasis Security, prompt injection and data exfiltration in a chat assistant, primary source, 18 March 2026.
RevocationStated
The vendor fixed the injection path after coordinated disclosure.Oasis Security, prompt injection and data exfiltration in a chat assistant, primary source, 18 March 2026.
AccountabilityStated
Named researchers, a coordinated timeline and named vendor fixes.Oasis Security, prompt injection and data exfiltration in a chat assistant, primary source, 18 March 2026.

What it changes

For a team deploying an agent

Note what the egress limit bought: the attacker could not reach an arbitrary server, so the theft had to cross an endpoint the vendor controls and monitors. That is what a limit is worth when injection succeeds anyway. Apply the same shape yourself: a strict outbound allowlist around anything that executes code for an agent, and no long conversation history in reach of a session opened from a link.

Sources

What this record was verified against

  1. Oasis Security, prompt injection and data exfiltration in a chat assistantPrimary · 18 March 2026

Related

Cite this record

Free to reuse under CC BY 4.0, with attribution. The record ID AIL-2026-0017 is permanent and is never reused.

In a sentence
According to the GAGE Agent Incident Ledger (as of 15 September 2026), a chat assistant was steered into searching a user's own history and uploading it through an allowed endpoint.
APA
GAGE (Global Academy of Generative-AI Education). (2026). A chat assistant was steered into searching a user's own history and uploading it through an allowed endpoint. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0017-claude-ai-chat-history-exfiltrated-through-allowed-endpoint
MLA
"A chat assistant was steered into searching a user's own history and uploading it through an allowed endpoint." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0017-claude-ai-chat-history-exfiltrated-through-allowed-endpoint.
Chicago
GAGE (Global Academy of Generative-AI Education). "A chat assistant was steered into searching a user's own history and uploading it through an allowed endpoint." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0017-claude-ai-chat-history-exfiltrated-through-allowed-endpoint.
Permalink
https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0017-claude-ai-chat-history-exfiltrated-through-allowed-endpoint

Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.

Back to the full ledger, or every record for United States and every exfiltration record.

GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.