2026-10-11 17:12 UTC

Independent reproduction and vendor response will determine whether Claude Cowork's shared-root behavior permits a practical sandbox escape and requires an isolation fix.

state: expiredheat: lowuncertainty: highcontradictsscott: highagent-sandboxing coding-agent-security claude-coworkAccomplish AIAnthropic

What is this?

Security researchers reported an attack chain against Anthropic’s Claude Cowork for Windows that starts with local code execution and obtains root access inside its isolated Ubuntu VM, allegedly bypassing the intended containment boundary. The supplied results describe independent reporting of the flaw, but they do not clearly establish Accomplish AI’s role or include Anthropic’s response. The claimed February 6, 2026 fix is also weakly grounded here: the cited GitHub advisory concerns a different Claude Code vulnerability, CVE-2026-25725, rather than the case’s CVE-2026-46331.

Why it matters to Scott

If independently reproduced, the reported shared-root escape would directly challenge the load-bearing assumption in Scott’s Sandboxed Execution and padded-cell designs that agent-run code remains behind a hard isolation boundary; it could require changes to SiloOS/OpenClaw isolation and defense-in-depth controls. The contradiction remains provisional because the supplied evidence does not establish reproduction, Accomplish AI’s role, Anthropic’s response, or a fix for CVE-2026-46331.
ip:concept.sandboxed-executionip:framework.siloosip:concept.defense-in-depthdev:project.silo-osdev:concept.padded-cell-agent-architecturedev:project.openclawradar:concept.agent-securityradar:concept.coding-agentsradar:person.anthropic
queries asked of Scott's wikis
  • coding-agent sandbox trust boundaries
  • shared-root isolation and privilege escalation
  • agent execution containment architecture
  • local code execution threat model for agents
  • sandbox escape disclosure and vendor verification
  • VM isolation versus process sandboxing

Measured heat

no measured readings yet — the hourly heat pass fills this in

How the heat travelled

no chain yet — the hourly chain pass fills this in

Evidence (6) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnSharedRoot; Escaping the Claude Cowork Sandboxaviramha50
🟧 echo.blog ⭐Original Accomplish research post by Oren Yomtov. It reports an end-to-end Claude Cowork escape using CVE-2026-46331, concluding that a guesAccomplish——
🟠 redditWhat SharedRoot reveals about securing autonomous AI agents
artificial
NapierPalm10
🟧 hnSharedRoot; Escaping the Claude Cowork Sandboxilreb10
🟧 hnEscaping Claude Cowork's local VM sandbox via CVE-2026-46331_orcaman_10
🟠 redditClaude Cowork Escaped Sandbox on Mac, Gained Full Access to All Files
ClaudeAI
flagnab09

Interpretation history

Decision trace