Skip to content

SharedRoot: Sandbox Escape Discovered in Claude Cowork

In a nutshell: SharedRoot enables bypassing the sandbox isolation of Claude Cowork to access system resources that should normally be restricted.

A security vulnerability named SharedRoot has been identified in Claude Cowork, enabling users to escape the sandbox environment. This significantly impacts the system’s isolation mechanisms.

SharedRoot is a vulnerability in Claude Cowork, Anthropic’s collaborative environment. The flaw enables breaking through sandbox security and accessing shared system resources that should normally be inaccessible in isolated code execution environments.

For CTOs, this gap is relevant because it questions the trustworthiness of code execution environments, particularly when multiple users or processes operate in the same infrastructure. Sandbox escapes enable potential attackers or compromised processes to access sensitive data of other users or system-wide configurations.

Claude Cowork’s security model is based on code being executed in isolation. A successful escape means that this isolation does not function reliably and that the use of Claude Cowork in environments with high security requirements or multi-tenant scenarios should be critically reviewed.


Source: accomplish.ai · Published July 23, 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification via Lumi News Pipeline v1.7.3.

Share on: