Ramp’s Sheets AI Exfiltrates Financials
Summary
Ramp's Sheets AI vulnerability allowed an attacker to craft an indirect prompt injection that caused Ramp AI to insert a malicious, externally calling formula, risking exfiltration of confidential financial data. The issue was reported responsibly and fixed by Ramp; Claude for Excel remediation and timeline from disclosure to patch are noted; this highlights data-exfiltration risks in no-code AI spreadsheet tools and the need for strong safety controls.