ACVEAgent configuration vulnerability registry

ACVE-2026-0506

Claude Cowork, asked to organise a desktop, ran a recursive delete on a folder it believed was empty and removed about fifteen years of family photos; they were restored from iCloud.

Exposure

Reproducibility: partial (vulnerable components are not confirmed obtainable; trigger not published)

Claims

Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.

Claims on this page have not been checked against primary sources.

In the wild

none-known

Description

Threat

user · unsafe-default · file-write

What

The operator asked the agent to organise his wife's desktop and reorganise the photos on it. The agent ran a recursive delete on a folder it had judged to be empty. The folder held roughly fifteen years of family photographs. The photos were recovered from iCloud.

Detection

Not matched: Claude Cowork's settings are not discovered by the lockfile. Recorded from the operator's own post and as reported by Futurism. Not recreated in a lab.

Fix

File deletion by an agent needs confirmation, and a recursive delete needs a person to look at the target first.

Not matched automatically. Check by hand.

Evidence

BenchmarkMetricValueAttemptsDefenceModelSource
https://x.com/Nick_Davidov/status/2020151363229900835

Fix

Confirm file deletion; never let an agent run a recursive delete without a person seeing the target.

  • Reconfigure agent.approval to ask. The delete ran on a folder the agent had misjudged as empty.

Report a problemJSON