Drooid Logo
Back to story perspectives

Full Breakdown

Critical Vulnerability in Claude Desktop Extensions Exposes Users to Remote Code Execution

2/10/2026, 12:15:49 PM

Overview of the Vulnerability

A significant security vulnerability has been identified in Claude Desktop Extensions (DXT), affecting over 10,000 users. Security researchers from LayerX reported that a single Google Calendar event could compromise systems running Claude DXT, which operates without traditional browser sandboxing and with full system privileges. This vulnerability has been assigned a maximum severity rating of 10.0 on the Common Vulnerability Scoring System (CVSS).

Mechanism of Exploitation

The vulnerability arises from the Model Context Protocol (MCP) utilized by Claude DXT, which allows the AI to autonomously combine low-risk data sources, such as Google Calendar, with high-risk actions, like executing local code. This design flaw means that an attacker could craft a seemingly innocuous calendar event containing malicious instructions, which Claude DXT would execute without user awareness. As a result, this could lead to full remote code execution on the victim's system, enabling unauthorized access to sensitive files, execution of system commands, and modification of operating system settings.

Official Response from Anthropic

LayerX reported the vulnerability to Anthropic, the company behind Claude DXT. However, Anthropic declined to address the issue, stating that it "falls outside our current threat model." Anthropic emphasized that users maintain control over which MCP servers they enable and the permissions granted, suggesting that the security boundary is defined by user configurations and existing system security controls.

Criticism and Industry Debate

The decision by Anthropic not to rectify the vulnerability has sparked debate within the cybersecurity community regarding the responsibilities of AI vendors versus Chief Information Security Officers (CISOs). Critics argue that AI vendors should ensure their products are secure by default, while others contend that it is the responsibility of organizations to adjust settings to fit their security needs. LayerX's findings highlight the potential for significant trust boundary violations in workflows driven by large language models (LLMs), raising concerns about the safety of MCP connectors in security-sensitive environments.

Conflicting Reports & Gaps

While LayerX has provided a detailed analysis of the vulnerability and its implications, Anthropic's stance suggests a divergence in understanding the threat landscape. The lack of action from Anthropic raises questions about the adequacy of their threat model and the potential risks posed to users who may not be aware of the vulnerabilities inherent in the system.

Verbatim Quotes

  • “If exploited by a bad actor, even a benign prompt, coupled with a maliciously worded calendar event, is sufficient to trigger arbitrary local code execution that compromises the entire system.” — Roy Paz, Principal Security Researcher at LayerX
  • “ "Claude Desktop's MCP integration is designed as a local development tool that operates within the user's own environment.” — Anthropic

This vulnerability in Claude DXT underscores the need for heightened security measures in AI-driven applications, particularly those that operate with extensive system privileges.