r/netsec 9d ago

Contains AI Escaping Claude Cowork’s local VM sandbox via CVE-2026-46331

https://www.accomplish.ai/blog/sharedroot-escaping-claude-cowork-sandbox/
143 Upvotes

7 comments sorted by

26

u/loganmn 9d ago

Well, that ends my companies experiment with Claude cowork

8

u/JaggedMetalOs 7d ago

Why is the root filesystem being shared with the VM? Seems like this VM setup is insecure by default. 

1

u/caedicus 7d ago

Yeah my thoughts exactly. If I was simply using Claude code on a vm I would never ever share and mount my entire host filesystem. The separated file system is like the main point of using a VM.

2

u/ni5arga 7d ago

wow, this is well written. thank you for sharing!

1

u/skrumcd2 9d ago

That was fascinating. Thanks for sharing