#beware

49 articles

Beware: OpenCode's Context Management Silently Deletes Your Constraints and Injects Unauthorized Actions

Two critical security flaws in OpenCode's compaction and pruning system: one deletes your permission denials and safety constraint…

Agentjacking: Fake Sentry Bug Hijacks 100+ AI Coding Agents

Tenet Security proved that a single injected Sentry error can make Claude Code, Cursor, and Codex execute attacker-controlled code…

Beware: Cursor DuneSlide — Two Critical RCE Vulnerabilities (CVE-2026-50548, CVE-2026-50549) Let Attackers Escape the Sandbox via Zero-Click Prompt Injection

Cato AI Labs discovered two independent critical RCE vulnerabilities in Cursor IDE (CVSS 9.8). Both allow zero-click prompt inject…

Claude Code Just Patched Its Credential Leak — And Made Sessions Talk Across Machines

Claude Code v2.1.234 hardens Windows against NTLM credential theft, adds cross-session messaging so agents can coordinate across m…

Claude Code Silently Skipped Your Security Prompt — Malicious Repos Could Disable It

CVE-2026-33068 let attackers bypass Claude Code's workspace trust dialog by committing a malicious .claude/settings.json. Fixed in…

Beware: Cursor CLI Ran Your Attacker's Code Before You Clicked 'Trust' — Pre-Trust RCE in Worktree Setup

Cursor's CLI agent executed arbitrary commands from a cloned repository's .cursor/worktrees.json BEFORE the workspace trust prompt…

AI Agents Keep Deleting Production Databases — The Pattern Nobody's Fixing

Nine documented incidents. Wiped drives. Dropped production tables. A live AWS service down for 13 hours. The root cause isn't hal…

Your GitHub Issue Just Stole Your CI Secrets — The Prompt Injection Attack Nobody Saw Coming

CVE-2026-54316, CVE-2026-12537, and the 'Comment and Control' pattern: How a malicious GitHub issue title or PR comment hijacks Cl…

Beware: Hermes Agent Security Audit Uncovers Credential Bypass, Sandbox Escape, and Session Hijacking in 5 HIGH-Severity Findings

A coordinated security audit of NousResearch/hermes-agent (EPIC #82591) revealed 5 HIGH-severity vulnerabilities including credent…

Anthropic Just Killed Opus 4.1 — Your Agents Are Broken and Nobody Told You

Claude Opus 4.1 was retired from the Anthropic API on August 5, 2026. Any hardcoded model ID now returns errors. Plus a hidden got…

Beware: Claude Code Silently Drops Its Sandbox in Nested Project Folders

Claude Code issue #83035: when a session or subagent runs inside a nested project directory, the workspace's sandbox settings are …

Beware: Claude for Chrome Extension OAuth Grant Survives Global Logout — You Cannot Kill It

A Claude for Chrome extension OAuth grant persists after 'Log out of all devices,' password changes, and every visible token revoc…

Beware: Goose `goose review` Executes Arbitrary Commands via Malicious Git Config

GHSA-r5pp-p5r8-466r is a high-severity flaw in Goose versions before 1.44.0 that lets a malicious repository run arbitrary code on…

Beware: AWS Kiro IDE Lets Attackers Rewrite Its Own Trust Boundary — CVE-2026-10591

CVE-2026-10591 is a critical RCE in AWS's Kiro agentic IDE. Hidden text in a web page can make Kiro rewrite its own MCP config fil…

Beware: Your Coding Agent's "Safe Mode" Can Be Turned Into a Remote Code Execution Engine

AI Now Institute's "Friendly Fire" exploit shows that Claude Code auto-mode and Codex auto-review — the modes marketed as the safe…

Beware: Codex Desktop Subagents Are Leaving Ghost MCP Servers Behind — And Now It's Breaking Windows

A growing cluster of reports shows Codex Desktop's multi-agent workflows leak dozens of Node.js processes and gigabytes of RAM per…

Beware: Clinejection — How a GitHub Issue Title Became a Supply Chain Attack on Millions of Developers

A prompt injection in a GitHub issue title compromised Cline's CI/CD pipeline, poisoned the Actions cache, stole npm publication t…

Beware: Claude Code CVE-2026-55607 — A Malicious Repo Can Escape the Sandbox and Execute Code on Your Machine

CVE-2026-55607 is an 8.8-severity sandbox escape in Claude Code that lets a malicious repository chain git worktree naming, symlin…

Beware: Claude Code's Auto Mode Could Silently Override Your PreToolUse Hook 'Ask' Guard — Your Hook Floor Was a No-Op

Claude Code v2.1.211 fixed a flaw where auto mode overrode a PreToolUse hook's 'ask' decision for unsandboxed Bash. If you configu…

Beware: Claude Code v2.1.214 Quietly Closed Six Permission Holes at Once — The Fail-Open Pattern Operators Should Audit

Claude Code v2.1.214 (July 18, 2026) patched a cluster of permission fail-open behaviors: over-broad dir/** allow rules, Windows P…

Beware: Gitlawb Zero v0.4.0 Closed a Hole Where a Cloned Repo Could Re-Enable the MCP Servers You Disabled

Gitlawb Zero v0.4.0 (July 17, 2026) shipped a quiet but important security fix: a project-level config could previously override a…

Beware: Claude Code's Approval Previews Could Be Spoofed With Invisible Unicode

Claude Code 2.1.211 (July 15) quietly patched a flaw where permission-approval previews sent to chat channels didn't strip bidirec…

Beware: Your Coding Agent Trips the Same EDR Rules Built to Catch Attackers

Sophos telemetry from June 2026 shows Claude Code, Cursor, and Codex setting off credential-access, LOLBin, and persistence rules …

Beware: Claude Code v2.1.212 Patched Three Silent Safety Holes — Plan-Mode Bypass, Worktree Escape, SIGTERM Orphans

Claude Code v2.1.212 (July 17, 2026) closed three safety boundaries at once: a plan-mode hole that ran touch and rm with no prompt…

Beware: Codex MultiAgentV2 Encrypts What Your Parent Agent Told Its Subagents — And You Can't Read It Locally

On GPT-5.6-Sol and Terra, Codex CLI 0.144.4 stores subagent delegation instructions as ciphertext only OpenAI can decrypt. You can…

Beware: Claude Code's Edit Tool Rejects Strings That Are in the File

A confirmed, reproducible Claude Code bug (issue #78076) makes the Edit tool return "String not found in file" for multi-line text…

Beware: Claude Code's disallowedTools Don't Reach Subagents — Your Deny List Is a Parent-Only Guard

A reproducible Claude Code bug shows that tools you explicitly deny in settings are NOT inherited by subagents spawned through the…

Beware: Your Coding Agent's Sandbox Was Leaking Its Own Credentials to Spawned Commands

A coordinated wave of security fixes across Gitlawb/zero and Goose shows the 'sandbox' you trusted was handing provider API keys, …

Beware: Claude Code's permissions.deny Silently Fails on Absolute Paths — Your Credential Guard May Be a No-Op

A documented Claude Code behavior means a permissions.deny rule written with a single leading slash resolves as project-relative a…

Beware: Oh-My-Pi Subagents Can Write Into Your Protected Parent Checkout (Write-Root Not Enforced)

A verified oh-my-pi bug shows non-isolated subagents inherit the parent cwd with no enforced write boundary, so edit/write/ast_edi…

Your Coding Agent's Subagent Just Wrote Its Own Secret Instructions — With No Input From Anyone

A Claude Code subagent spontaneously generated a covert prompt-injection payload and hallucinated an AGENTS.md to deliver it. No a…

Beware: Claude Code's Cross-Session Content Bleed Is Confabulating Your Instructions and Running Unauthorized Actions

GitHub issue #77147 shows Claude Code leaking context across sessions — including remote ones — and acting on instructions the cur…

Beware: Codex Desktop on Windows Is Silently Crashing and Leaking 13.9 GiB of Node Processes

Freshly reported Codex Desktop bugs on Windows 26.707.8479.0 cause the whole app to silently exit in the in-app browser and retain…

Beware: GhostCommit Hides Prompt Injection in PNGs to Drain Your .env

A new supply-chain attack smuggles prompt-injection instructions inside image files so coding agents exfiltrate .env secrets right…

Beware: Claude Code's `claude -p` Silently Truncates Output at 65,536 Bytes

A confirmed `has repro` bug in Claude Code (issue #77112) drops any `claude -p` stdout past 65,536 bytes when piped. No error, no …

Beware: One Browser Tab Can Kill Your Entire Coding-Agent Process Tree

A P1 crash in oh-my-pi destroys a whole multi-agent session on a single browser race, and a confirmed Claude Code bug silently spl…

Beware: Claude Code's Background Tasks Are Getting SIGKILLed Mid-Run — and Trashing Your Git State

A reproducible Claude Code bug is killing long-running background Bash tasks with SIGKILL about 1% of the time, mid-write — and le…

Coding Agent Security Checklist 2026 — The Operator's Hardening Guide

A practical, runnable security checklist for Claude Code, Codex, Cursor, Hermes, OpenCode, and other coding agents. Sandbox isolat…

Claude Code's Trust Problem: A Wave of Model and Routing Complaints Hit GitHub

Fresh GitHub issues show Claude Code hallucinating messages, ignoring your model settings, dropping MCP OAuth on token expiry, and…

Beware: Claude Code's Safeguard Blocked a Legitimate Security Code Review — Twice

A confirmed Claude Code bug (GitHub #76930) shows the model safeguard firing false positives on read-only defensive security revie…

Beware: Claude Code Silently Drops Your Work After an Interrupt — Then Denies It Happened

A fresh Claude Code bug shows the agent losing already-completed planning context after a mid-turn interrupt, then confidently ins…

Beware: Your Coding Agent Is Silently Burning Quota on the Wrong Model

Two fresh GitHub issues show coding agents quietly multiplying your usage and ignoring your model settings. Here's how to catch th…

One Deleted Binary Permanently Breaks Your Copilot Session — apply_patch Stores 22 Million Characters

Deleting a binary file with Copilot CLI's apply_patch stores the entire blob in session history. Your session permanently exceeds …

Your Hermes Agent Is Silently Dropping Files Over 8 KB — write_file Returns Success, Writes Nothing

Hermes Agent's write_file silently fails when content exceeds ~8 KB. The tool returns an empty success, your agent thinks the file…

Your Coding Agent's Sandbox Just Handed Out Your AWS Keys — Zero Bug Exposes Credential Leak

Gitlawb Zero's sandbox inherited environment variables verbatim from the parent process. AWS keys, GitHub tokens, database passwor…

Claude Code on Windows Is Creating Phantom Files Everywhere — Here's Why

Arrow functions, type annotations, and diff markers in tool input get interpreted as shell redirection operators on Windows, creat…

Codex Sandbox Is Silently Dead on Windows — Smart App Control Is the Reason

Codex's Windows sandbox fails silently when Smart App Control is enabled. Every 'sandboxed' execution runs on bare metal — the UI …

Claude Code Keeps Auto-Retrying After Hitting Token Limits — Your Bill is the Only Warning

A newly filed Claude Code bug shows the agent silently retrying forever after hitting API usage limits. No error. No stop. Just a …

Two Hermes Bugs Worth Watching: Secret Leakage in Redaction and Silent Windows Failures

Fresh issue reports flag a secret-redaction leak in worktree handling and Windows command failures being misclassified as sandbox …