Researchers Find Matching RCE Flaws in Claude Code, Gemini CLI and Codex Coding Agents
Security researcher Elad Meged has uncovered a strikingly similar vulnerability pattern across AI coding agents from Anthropic, Google, and OpenAI, all traceable to how each vendor’s surrounding ‘harness’ handles tool permissions rather than flaws in the underlying models. The bugs allowed remote code execution and credential theft triggered by nothing more than an anonymous GitHub issue.
Itagora tiene in archivio titolo e sommario per la ricerca interna. Il testo completo resta sulla fonte. Il link in uscita non invia referrer.