Anthropic fixed a Claude Desktop macOS flaw where a file an injected agent left in a Cowork folder could run commands when opened. Fixed in 1.15962.0.
Anthropic has published a high-severity advisory, GHSA-v234-4jrq-mgg6, for Claude Desktop on macOS. A gap in the app's protection around Cowork shared folders meant that a file written there by a compromised or prompt-injected agent could run commands on the user's Mac if the user opened it from Claude Desktop. Versions from 1.1.3918 up to but not including 1.15962.0 are affected. The fix is in 1.15962.0. The advisory was published on 25 September 2026 and lists no CVE identifier.
Who is affected
The advisory covers Claude Desktop on macOS, builds >= 1.1.3918 and < 1.15962.0. Anthropic says users on standard auto-update have already received the fix. Those who update manually or through managed deployment are advised to move to the latest version, and 1.15962.0 is the first fixed build. The advisory mentions no workarounds.
What went wrong
Claude Desktop keeps a list of file types that execute code when opened, and it refuses to open those types directly from a Cowork session's shared folder. The purpose, in the advisory's words, is to ensure that content an agent writes into the folder from inside the Cowork sandbox cannot execute on the host unless the user intends to run it.
On macOS, that list left out one file type that the operating system executes on open. The advisory does not name the type. A file of that kind, placed in a Cowork folder by a compromised or prompt-injected agent, could therefore run commands on the user's Mac when opened from Claude Desktop. Version 1.15962.0 adds that type and related types to the block list. The advisory classifies the weakness as CWE-184, Incomplete List of Disallowed Inputs.
Severity and the user-interaction requirement
The advisory rates the issue High, with a CVSS 4.0 score of 8.5 and the vector CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. That is local attack vector, low complexity, no privileges required, passive user interaction, and high impact on confidentiality, integrity and availability.
The interaction requirement matters. In the base case the user has to open the file from Claude Desktop. The attacker also needs an agent in the Cowork session that is compromised or has been prompt-injected, since that is how the file reaches the shared folder.
The advisory describes one chained scenario in which the user does not act. Claude Desktop releases before 1.11847.5 shipped a Cowork VM image whose guest Linux kernel was affected by upstream vulnerability CVE-2026-43284. Version 1.11847.5, released 9 June 2026, updated the image to a patched kernel. The advisory says that, combined with the file-handling issue, code that had gained elevated privileges inside the VM could trigger the file open without user interaction. The advisory ties that scenario to the earlier VM kernel issue, which builds from 1.11847.5 onward have patched, and says the severity rating reflects the file-handling issue on its own.
Credit
The advisory says Anthropic identified the issue internally. Vladimir Tokarev of Cyera Research reported it independently.
A separate, low-severity fix in Claude Code
Four days later Anthropic published GHSA-gfvf-j8jh-jxxw, CVE-2026-103012, for a different product: the npm package @anthropic-ai/claude-code. It is rated Low (CVSS 4.0 score 2.0) and affects versions >= 2.0.68 and < 2.1.260. It is fixed in 2.1.260.
Claude Code could select a stored API key, left from an earlier /login or set directly, over a valid Claude Enterprise or Team sign-in when fetching the organization's server-managed settings. The settings endpoint rejected the key, even though the session itself authenticated with the Enterprise or Team account. The session then started without the organization's server-managed policies, such as permission deny rules, model restrictions and managed-only locks. Where cached settings already existed, those copies stayed in place without receiving later policy updates.
The advisory says exploitation requires local access to a device with a stored API key, and for the no-policy case, no previously cached managed settings on the machine. Endpoint-managed settings, delivered by MDM or files, are not affected. Organizations on Claude for Enterprise are affected from 2.0.68 onward. Claude for Work (Teams) is affected from 2.1.38, when server-managed settings became available. The advisory credits Tamas Voros of the NVIDIA AI Red Team. This issue is not part of the Claude Desktop flaw.
What defenders should do
- Confirm Claude Desktop on every Mac is at 1.15962.0 or later, particularly where updates are managed or pinned.
- Treat files in Cowork shared folders as untrusted output from an agent, especially in sessions that process external content. Do not open them from the app unless you know what they are.
- Make sure no installation is older than 1.11847.5, the build that patched the VM kernel issue the advisory describes.
- For Claude Code, update to 2.1.260 or later. Where server-managed settings matter, check whether developer machines hold stored API keys, and consider endpoint-managed settings, which the advisory says were unaffected.