Plugin4Shell Exposes AI Coding Agents to RCE
A zero-click remote code execution flaw in popular AI coding agents could let attackers run malicious code without developer interaction, researchers warn.
6 results for “coding agents”
A zero-click remote code execution flaw in popular AI coding agents could let attackers run malicious code without developer interaction, researchers warn.
Two Docker Sandboxes vulnerabilities let malicious guest code read or modify macOS host files, with fixes shipped in version 0.42.0.
Malicious MCP servers can split instructions to make AI coding agents exfiltrate secrets, ASSET reports.
Anthropic makes auto mode the default in Claude Code from August 14, claiming its classifier is safer than human approval.
Researchers identify a recurring security flaw where AI agents blindly execute commands based on predictable, hallucinated names.
Researchers discover a critical vulnerability where AI coding agents are tricked into executing malicious code via hallucinations.