logo

Vulnerability in Anthropic’s Claude Code Shows Up in Cowork

ID: 0c25e0c5-e50c-509e-90cc-b65a33ae99c0

STIX ID: report--0c25e0c5-e50c-509e-90cc-b65a33ae99c0

Feed Name: Security Boulevard

Threat Score
65/100

Date Published: 2026-01-16

Date Updated: 2026-04-22

Author: Jeffrey Burt

...
...

Anthropic released a research preview of Claude Cowork—an AI agent that can access and manipulate local files—but researchers from PromptArmor demonstrated a vulnerability where malicious prompt injections in uploaded files can coerce Cowork to call Anthropic's file upload API (using an attacker-supplied API key) and exfiltrate sensitive local files. The flaw mirrors a known issue in Claude Code, effectively bypasses VM network restrictions by abusing a trusted Anthropic endpoint, and is especially dangerous for non-technical users who may not recognize malicious actions; Anthropic has warned users to limit folder and connector access while the feature is in preview.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.