Story perspectives
Critical LayerX Vulnerability Threatens 10,000 Users' Security
2/10/2026
1 of 1
Story summary
- LayerX disclosed a critical vulnerability in Claude Desktop Extensions (DXT) that could allow malicious calendar events to execute arbitrary code, CVSS 10.0, affecting over 10,000 users.
- DXT operates without sandboxing, granting full system privileges.
- LayerX reported the issue to Anthropic, which declined to address it, citing it as outside their threat model.
- The disclosure raises questions about responsibility and increases concern over LLM-driven workflow security.
