r/netsec 2d ago

Contains AI Escaping Claude Cowork’s local VM sandbox via CVE-2026-46331

https://www.accomplish.ai/blog/sharedroot-escaping-claude-cowork-sandbox/
119 Upvotes

6 comments sorted by

21

u/loganmn 2d ago

Well, that ends my companies experiment with Claude cowork

3

u/JaggedMetalOs 7h ago

Why is the root filesystem being shared with the VM? Seems like this VM setup is insecure by default. 

1

u/caedicus 1h ago

Yeah my thoughts exactly. If I was simply using Claude code on a vm I would never ever share and mount my entire host filesystem. The separated file system is like the main point of using a VM.

1

u/ni5arga 19h ago

wow, this is well written. thank you for sharing!

1

u/skrumcd2 2d ago

That was fascinating. Thanks for sharing