Link following in Claude Desktop - CVE-2026-44470
Published: May 7, 2026
Claude Desktop
Detailed vulnerability description
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to improper link resolution before file access in CoworkVMService when creating files within the VM bundle directory. A local user can replace the user-writable VM bundle directory with a directory junction pointing to an attacker-chosen location to escalate privileges.
The issue affects Claude Desktop for Windows because the service runs as SYSTEM and may create a SYSTEM-owned file in an arbitrary directory.