Claude Desktop (macOS): opening a malicious file from a Cowork folder could run commands on the host
High8.5Published Sep 25, 2026
Claude Desktop maintains a list of file types that execute code when opened, and prevents those types from being opened directly from a Cowork session's shared folder. This ensures that content written into the folder by an agent running inside the Cowork sandbox cannot execute on the host without the user intending to run it. On macOS, this list omitted a file type that the operating system executes on open. As a result, a file placed in a Cowork folder by a compromised or prompt-injected agent could run commands on the user's Mac if the user opened that file from Claude Desktop. Claude Desktop 1.15962.0 adds this and related file types to the block list. Separately, Claude Desktop releases prior to 1.11847.5 shipped a Cowork VM image whose guest Linux kernel was affected by the upstream vulnerability CVE-2026-43284. Claude Desktop 1.11847.5 (released 9 June 2026) updated the VM image to a patched kernel. When the two issues were combined, code that had gained elevated privileges inside the VM could trigger the file open without user interaction; the severity rating above reflects the file-handling issue on its own. Claude Desktop 1.15962.0 and later include both changes. Users ...
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Claude Desktop Product | >= 1.1.3918, < 1.15962.0 | 1.15962.0 |
Details and references
Claude Desktop maintains a list of file types that execute code when opened, and prevents those types from being opened directly from a Cowork session's shared folder. This ensures that content written into the folder by an agent running inside the Cowork sandbox cannot execute on the host without the user intending to run it. On macOS, this list omitted a file type that the operating system executes on open. As a result, a file placed in a Cowork folder by a compromised or prompt-injected agent could run commands on the user's Mac if the user opened that file from Claude Desktop. Claude Desktop 1.15962.0 adds this and related file types to the block list. Separately, Claude Desktop releases prior to 1.11847.5 shipped a Cowork VM image whose guest Linux kernel was affected by the upstream vulnerability CVE-2026-43284. Claude Desktop 1.11847.5 (released 9 June 2026) updated the VM image to a patched kernel. When the two issues were combined, code that had gained elevated privileges inside the VM could trigger the file open without user interaction; the severity rating above reflects the file-handling issue on its own. Claude Desktop 1.15962.0 and later include both changes. Users on standard Claude Desktop auto-update have already received these fixes. Users performing manual or managed updates are advised to update to the latest version. Identified internally by Anthropic. Also independently reported by Vladimir Tokarev (Cyera Research).
- CVSS 4.0
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-184
More Anthropic advisories
All Anthropic| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 12 | Argument Injection via resume Option Allows Arbitrary Command Execution | Critical9.2 | 0.2.121 |
| Jul 1 | Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded Allocation | Medium6.3 | 0.8.0+1 more |
| Jul 1 | Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in Deref | Medium5.9 | 0.7.0 |
| Jun 25 | Insecure Temporary File in /copy Command Enables Response Disclosure and Symlink-Based File Write | Medium4.4 | 2.1.128 |
| Jun 25 | Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution | High7.7 | 2.1.163 |
| Jun 13 | Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch | Medium6.0 | 2.1.163 |