Claude Cowork, a general-purpose AI agent, is vulnerable to file exfiltration attacks via indirect prompt injection due to unresolved isolation flaws in its code execution environment. This vulnerability allows attackers to upload files to their Anthropic account, potentially exposing sensitive user data. The attack exploits the allowlisting of the Anthropic API, which is trusted by Claude's VM environment. The vulnerability was previously identified in Claude.ai chat and was acknowledged but not remediated by Anthropic.