Skip to content
AnthropicGHSA-v234-4jrq-mgg6

Claude Desktop (macOS): opening a malicious file from a Cowork folder could run commands on the host

High8.5Published Sep 25, 2026

Claude Desktop maintains a list of file types that execute code when opened, and prevents those types from being opened directly from a Cowork session's shared folder. This ensures that content written into the folder by an agent running inside the Cowork sandbox cannot execute on the host without the user intending to run it. On macOS, this list omitted a file type that the operating system executes on open. As a result, a file placed in a Cowork folder by a compromised or prompt-injected agent could run commands on the user's Mac if the user opened that file from Claude Desktop. Claude Desktop 1.15962.0 adds this and related file types to the block list. Separately, Claude Desktop releases prior to 1.11847.5 shipped a Cowork VM image whose guest Linux kernel was affected by the upstream vulnerability CVE-2026-43284. Claude Desktop 1.11847.5 (released 9 June 2026) updated the VM image to a patched kernel. When the two issues were combined, code that had gained elevated privileges inside the VM could trigger the file open without user interaction; the severity rating above reflects the file-handling issue on its own. Claude Desktop 1.15962.0 and later include both changes. Users ...

GitHub advisory

Affected versions

PackageAffectedFixed in
Claude Desktop
Product
>= 1.1.3918, < 1.15962.01.15962.0
Details and references

Claude Desktop maintains a list of file types that execute code when opened, and prevents those types from being opened directly from a Cowork session's shared folder. This ensures that content written into the folder by an agent running inside the Cowork sandbox cannot execute on the host without the user intending to run it. On macOS, this list omitted a file type that the operating system executes on open. As a result, a file placed in a Cowork folder by a compromised or prompt-injected agent could run commands on the user's Mac if the user opened that file from Claude Desktop. Claude Desktop 1.15962.0 adds this and related file types to the block list. Separately, Claude Desktop releases prior to 1.11847.5 shipped a Cowork VM image whose guest Linux kernel was affected by the upstream vulnerability CVE-2026-43284. Claude Desktop 1.11847.5 (released 9 June 2026) updated the VM image to a patched kernel. When the two issues were combined, code that had gained elevated privileges inside the VM could trigger the file open without user interaction; the severity rating above reflects the file-handling issue on its own. Claude Desktop 1.15962.0 and later include both changes. Users on standard Claude Desktop auto-update have already received these fixes. Users performing manual or managed updates are advised to update to the latest version. Identified internally by Anthropic. Also independently reported by Vladimir Tokarev (Cyera Research).

CVSS 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-184

More Anthropic advisories

All Anthropic

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.