CVE-2026-7574: Anthropic Claude Desktop Cowork VM Image Contents Not Validated Before Use
This disclosure documents a local image tampering vulnerability in Anthropic Claude Desktop’s Cowork virtual machine lifecycle.
AHA! has discovered an issue with Claude Desktop from Anthropic and is publishing this disclosure in accordance with AHA!’s standard disclosure policy today, on 2026-06-23. CVE-2026-7574 has been assigned to this issue.
This vulnerability is estimated to have a CVSSv3.1 rating of AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L (8.7, High), and the relevant SSVC vectors are Exploitation: PoC and Technical Impact: Total.
