[REVISION HISTORY]
Security vulnerabilities in AI agents and assistants
Updated 2 times since CLSTR started tracking revisions of this situation.
What changed
2026-09-21 11:54 UTC → 2026-09-25 00:28 UTC ·
added
removed
Security researchers have identified critical vulnerabilities affecting various AI agents and assistants. Initially, researchers at Air discovered ‘Plugin4Shell’, a flaw in the SHA-pinning mechanism used by AI coding agents like Claude Code, Codex, Gemini CLI, and Microsoft Copilot. This vulnerability allows attackers to bypass plugin integrity verification and inject malicious code, posing a ‘zero-click’ threat to developer machines and corporate data. In response, Anthropic and OpenAI issued patches, Google deprecated the affected Gemini CLI, and Microsoft has yet to release a fix. Subsequently, researchers at Forever Security demonstrated ‘prompt-forcing’, a technique where malicious browser extensions can hijack AI assistants integrated into Chromium-based products. This vulnerability affects Gemini Live in Google Chrome, Perplexity Comet, Microsoft Edge, Opera Neon, and the Claude Chrome extension. By injecting code into trusted web pages, extensions can bypass security boundaries to issue commands. Reported impacts include the ability to read files, capture screens, activate microphones or cameras, and bypass task-execution restrictions. Building on this research, security researcher Gal Weizman of Forever Security identified a specific vulnerability named ‘BragJack’. This flaw allows malicious extensions to exploit the Chromium declarativeNetRequest (DNR) function to manipulate network requests and intercept traffic. This enables an attacker to take control of an AI agent, which can then use its privileges to read content, take screenshots, or interact with web pages without direct user intervention. The discovery resulted in two official CVEs, and both Google and Microsoft have since released patches to address these flaws. Recent findings have expanded the scope of risks to AI coding agents, specifically highlighting ‘conversation history poisoning’. Researchers demonstrated that agentic harnesses often store history in unverified local databases, such as SQLite, allowing attackers to inject fabricated data. This manipulation tricks the AI into following malicious instructions by making them appear as previously agreed-upon states.
Versions
- 2026-09-25 00:28 UTC Security vulnerabilities in AI agents and assistants
- 2026-09-21 11:54 UTC Security vulnerabilities in AI agents and assistants
- 2026-09-18 18:34 UTC Security vulnerabilities in AI agents and assistants
Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.