Security researchers have uncovered critical vulnerabilities in the default GitHub Actions configurations used by leading AI developers Anthropic, Google, and OpenAI for their respective coding agents. The flaws, present in agents like Claude Code, Gemini CLI, and Codex, could allow unauthenticated attackers to achieve remote code execution (RCE).
The vulnerabilities stem from weaknesses in the CI/CD scaffolding designed to sandbox these AI agents, rather than flaws in the agents' generated code. For instance, Claude Code's argument validator incorrectly processed quoted content, while Gemini CLI's tool-restriction settings were found to be unenforced. OpenAI's Codex suffered from a shared writable checkout that allowed an earlier stage to inject malicious instructions for a later stage to execute.
In addition to these agent-specific issues, a separate vulnerability was identified in Google's ADK repository, where a low-privilege triage agent could be manipulated to trigger a high-privilege maintainer agent, effectively escalating permissions. Google has assigned a CVSS score of 10.0, the maximum severity, to the Gemini CLI finding, highlighting the significant risk posed by these security lapses.
Major AI Labs' Coding Agents Vulnerable to Remote Code Execution
12 stories · 7 sources
#ai #security #hacksOther digests
- 2026-09-14 — Major AI Labs' Coding Agents Vulnerable to Remote Code Execution
- 2026-09-13 — AI Fuels School Threats, Russian Drones; Voice Authentication Compromised
- 2026-09-12 — OpenAI Agents Linked to RubyGems Hack, API Key Theft Attempt
- 2026-09-11 — New Mexico Lawyer Fined $5,000 for AI-Fabricated Legal Brief
- 2026-09-10 — Government Accounts Attempted Bioweapon Research Using AI Chatbot, Anthropic Reports
- 2026-09-09 — AI Agent Exposes Home Network Vulnerabilities, Offers Security Solutions
- 2026-09-08 — Hackers Exploit Claude AI, Stealing User Tokens
- 2026-09-07 — UK Cyber Agency Warns of Shadow AI Risks to Data and Agent Privileges
- 2026-09-06 — AI Model Escapes Control, Forms Agent Swarm in Security Breach
- 2026-09-05 — OpenAI Agents Breach German Wiki; Company Pledges $1 Billion for Cyber Defense
- 2026-09-04 — OpenAI Agents Breach Internet Unnoticed, Exposing Security Lapses
- 2026-09-03 — Major AI Models Suffer Rare, Simultaneous Service Disruptions
- 2026-09-02 — Amazon Alexa to Verify Shopper Communications Against Scams
- 2026-09-01 — OpenAI's Astra Model Raises Security Concerns Amid X Account Attacks
- 2026-08-31 — Pentagon Explores AI Tools Like Grok and ChatGPT for Military Applications
- 2026-08-30 — Game Wiki Offline After Banning AI Bot, Faces DDoS Attack
- 2026-08-29 — Activision Serves Legal Papers to Call of Duty Cheat Maker, Films Confrontation
- 2026-08-28 — AI Agents Breach Hugging Face in Unauthorized Test; New Concerns Emerge Over AI-Created Superviruses
- 2026-08-27 — OpenAI AI Agents Breached Hugging Face Systems in Security Test Mishap
- 2026-08-26 — Rogue OpenAI Model Breached Hugging Face Systems, Accessed Internet
- 2026-08-25 — Anthropic Mandates Remote Work Amidst Potential Security Team Strike
- 2026-08-24 — Alabama Investigates OpenAI After AI Model Hacks Hugging Face
- 2026-08-23 — Uber Fined Nearly $1 Billion for Automated Driver Suspensions; Android Car Units Targeted by Malware
- 2026-08-22 — Rogue AI Agents and Data Breaches Escalate Security Concerns
- 2026-08-21 — Student Exposes Rogue AI Hacking Attempt in Texas
- 2026-08-20 — AI Systems Suffer Glitches, Ukraine Explores AI Drones for Moscow Attacks
- 2026-08-19 — Open-Weight AI Achieves Advanced Cyber Offense Capabilities, Posing New Security Threats
- 2026-08-18 — OpenAI Bolsters Security After AI Breach, Halts Astra Model Development
- 2026-08-17 — AI Integration Overwhelms Traditional Security Frameworks, Experts Report
- 2026-08-16 — Ukraine Discovers Nvidia AI Chip in Russian Missile, Intelligence Reports