< Back to all clusters
[TECHNOLOGY] · 4 sources

started · updated

AI coding agents face critical security vulnerabilities

Security researchers have identified critical vulnerabilities in major AI coding agents, including Anthropic Claude Code, OpenAI Codex, AWS Kiro-CLI, Gemini CLI, and Copilot. These flaws expose developers to significant risks through two primary methods: conversation history poisoning and a vulnerability class dubbed ‘Plugin4Shell’.

In conversation history poisoning, researchers demonstrated that agentic harnesses often store conversation history in local, unverified databases like SQLite. An attacker can inject fabricated data into these databases, rewriting the AI’s perceived past to manipulate its future actions. This allows an attacker to trick an agent into following malicious instructions by making them appear as previously agreed-upon states.

Separately, the ‘Plugin4Shell’ vulnerability exploits flaws in how agents verify SHA-pinned plugin commits. While SHA-pinning is intended to ensure code immutability, some agents fail to strictly enforce hash matching or allow silent auto-updates that can swap benign plugins for malicious code. Because these tools often possess broad permissions to filesystems, credentials, and cloud accounts, such an exploit can grant attackers remote code execution (RCE) and access to sensitive development pipelines.

Entities

AWS · Anthropic · Darktrace · Google · OpenAI