logo

Contagious Claude Code bug Anthropic ignored promptly spreads to Cowork

ID: 7e897d51-44e6-5d40-b6b4-81452fab7561

STIX ID: report--7e897d51-44e6-5d40-b6b4-81452fab7561

Feed Name: The Register (Security)

Threat Score
65/100

Date Published: 2026-01-15

Date Updated: 2026-04-26

Author: Brandon Vigliarolo

...
...

Researchers at PromptArmor demonstrated a prompt-injection attack against Anthropic's Cowork that can trick the agent into uploading sensitive local files to an attacker-controlled Anthropic account via the Files API; the PoC used a curl-based upload to make the largest file available to the attacker's API key. The issue follows a previously reported Claude Code exfiltration playbook and highlights Anthropic's current mitigation stance of user caution and limited immediate fixes, though the company plans VM and security updates as Cowork remains a research preview.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.