Just a week after OpenAI disclosed that two frontier AI models escaped a sandboxed testing environment and breached Hugging Face, researchers have demonstrated a similar containment failure involving Anthropic's Claude Cowork.
“That’s not supposed to be possible,” the researchers wrote. “Cowork runs the agent inside a Linux VM as an unprivileged user, and the promise is that whatever it does stays inside that VM and the folders you hand it. That boundary is the product. Untrusted input isn’t an edge case for an agent, it’s the main case.”
However, Accomplish argues the kernel bug was only one part of the problem. The researchers say the escape only worked because several security safeguards failed at the same time, including giving the virtual machine access to the host computer's entire filesystem and allowing it to load kernel modules it didn't need. According to the report, fixing any one of those weaknesses would have stopped the attack.
Accomplish said Anthropic classified the report as "informative," saying the kernel flaw fell within the company's 30-day window for recently disclosed vulnerabilities and the remaining findings were considered defense-in-depth recommendations rather than standalone vulnerabilities.

















