A zero-click RCE flaw in AI coding agents could have exposed enterprise systems
This story is from 2026-09-17. It is preserved in the archive; the latest stories are on the live feed.
Popular AI coding agents such as OpenAI’s Codex, Anthropic’s Claude Code, Google’s Gemini CLI, and Microsoft-owned GitHub Copilot were vulnerable to a zero-click attack that enabled attackers to execute malicious code, even without developer interaction, by swapping a trusted plugin from an online…
Read the full story at InfoWorld AI ↗
Timeline · 2 reports
- 2026-09-18 15:39 · InfoWorld AI
A zero-click RCE flaw in AI coding agents could have exposed enterprise systems - 2026-09-17 14:22 · r/ChatGPTCoding
[ Agenteq ] A single canoncial source for AI coding agents rules