logo

Claude Cowork’s Sandbox Vulnerability Allows Attackers to Run Arbitrary Commands as Root

ID: 691a41fe-5521-5191-a599-c379ade33809

STIX ID: report--691a41fe-5521-5191-a599-c379ade33809

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-07-02

Date Updated: 2026-07-02

Author: Guru Baran

...
...

A technical analysis reveals a vulnerability chain in Anthropic's Claude Cowork (Windows) where attackers with local code execution can DLL-sideload a malicious USERENV.dll into claude.exe to run code as a signed process, then exploit a JSON-RPC 'spawn' parameter (isResume:true) to obtain a root shell inside the product's isolated Ubuntu VM, effectively bypassing multiple sandbox defenses; the chain was validated against Claude Desktop for Windows 1.9255.2.0.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.