AI-powered IDEs prompt-injection RCE and data-exfiltration flaws (multiple vulnerabilities)
Vulnerability
Summary
Hide ▲
Show ▼
A disclosed set of 30+ vulnerabilities in AI-powered IDEs and coding assistants creates data exfiltration and remote code execution risk across tools such as Cursor and GitHub Copilot. The flaws are chained through prompt injection and legitimate IDE features, and 24 CVEs have already been assigned. The disclosure shows that normal development workflows can be turned into attack paths when AI agents trust hostile context.
Related Happenings
CISA recommends continuous secrets scanning and stronger key management after GitHub leak
Defensive Guidance
H score26
First: 13.07.2026 18:03
Last: 13.07.2026 18:03
Sources 1
About this happening:
CISA now recommends continuous secrets scanning and stronger key management after a contractor left internal credentials in a public GitHub repository for nearly *...
CISA recommends continuous secrets scanning and stronger key management after GitHub leak
Defensive GuidanceAbout this happening: CISA now recommends continuous secrets scanning and stronger key management after a contractor left internal credentials in a public GitHub repository for nearly *...
Ghostcommit PNG-embedded prompt injection against AI code reviewers
Technical Analysis
H score25
First: 11.07.2026 12:03
Last: 11.07.2026 12:03
Sources 1
About this happening:
Researchers demonstrated Ghostcommit, a PNG-embedded prompt-injection technique that can bypass AI code review and leak .env secrets into committed source. The pay...
Ghostcommit PNG-embedded prompt injection against AI code reviewers
Technical AnalysisAbout this happening: Researchers demonstrated Ghostcommit, a PNG-embedded prompt-injection technique that can bypass AI code review and leak .env secrets into committed source. The pay...
Prompt-injection proof-of-concept enables silent RCE in Claude Code and Codex
Technical Analysis
H score28
First: 10.07.2026 16:45
Last: 10.07.2026 16:45
Sources 1
About this happening:
Researchers demonstrated a proof-of-concept exploit that can force remote code execution in Anthropic’s Claude Code and OpenAI’s Codex, exposing a trust-boundary f...
Prompt-injection proof-of-concept enables silent RCE in Claude Code and Codex
Technical AnalysisAbout this happening: Researchers demonstrated a proof-of-concept exploit that can force remote code execution in Anthropic’s Claude Code and OpenAI’s Codex, exposing a trust-boundary f...
Defensive guidance for splitting behavioral detections around AI coding agents on Windows endpoints
Defensive Guidance
H score28
First: 08.07.2026 20:02
Last: 08.07.2026 20:02
Sources 1
About this happening:
AI coding agents on Windows endpoints are triggering attacker-style detections, forcing defenders to separate benign automation from real credential theft risk. A June 2...
Defensive guidance for splitting behavioral detections around AI coding agents on Windows endpoints
Defensive GuidanceAbout this happening: AI coding agents on Windows endpoints are triggering attacker-style detections, forcing defenders to separate benign automation from real credential theft risk. A June 2...
HalluSquatting indirect prompt-injection attack on AI coding assistants
Technical Analysis
H score3
First: 08.07.2026 18:07
Last: 08.07.2026 18:07
Sources 1
About this happening:
Researchers demonstrated HalluSquatting, an indirect prompt-injection technique that can push AI coding assistants to fetch attacker-controlled resources and execute code....
HalluSquatting indirect prompt-injection attack on AI coding assistants
Technical AnalysisAbout this happening: Researchers demonstrated HalluSquatting, an indirect prompt-injection technique that can push AI coding assistants to fetch attacker-controlled resources and execute code....
Timeline
-
06.12.2025 17:24 2 articles · 7mo ago
IDEsaster disclosure of AI IDE vulnerabilities
Initial DisclosureSecurity researcher Ari Marzouk (MaccariTA) disclosed 30+ vulnerabilities in AI-powered IDEs and coding assistants, naming the issue set IDEsaster. The affected tools include Cursor, Windsurf, Kiro.dev, GitHub Copilot, Zed.dev, Roo Code, Junie, and Cline, and 24 of the issues received CVE identifiers. The disclosed attack chains combine prompt injection, auto-approved agent tool calls, and legitimate IDE features to leak sensitive files or achieve remote code execution.
Show sources
- Researchers Uncover 30+ Flaws in AI Coding Tools Enabling Data Theft and RCE Attacks — thehackernews.com — 06.12.2025 17:24
- Researchers Uncover 30+ Flaws in AI Coding Tools Enabling Data Theft and RCE Attacks — thehackernews.com — 06.12.2025 17:24