#cve

5 articles

Claude Code Silently Skipped Your Security Prompt — Malicious Repos Could Disable It

CVE-2026-33068 let attackers bypass Claude Code's workspace trust dialog by committing a malicious .claude/settings.json. Fixed in…

Your GitHub Issue Just Stole Your CI Secrets — The Prompt Injection Attack Nobody Saw Coming

CVE-2026-54316, CVE-2026-12537, and the 'Comment and Control' pattern: How a malicious GitHub issue title or PR comment hijacks Cl…

CVE-2026-69192: The '012.0.0.1' Address Bug That Sneaks Internal Servers Past Coding-Agent SSRF Filters

A parsing mismatch in the ip-address npm package can make your agent fetch an internal cloud-metadata server it meant to block. He…

Beware: AWS Kiro IDE Lets Attackers Rewrite Its Own Trust Boundary — CVE-2026-10591

CVE-2026-10591 is a critical RCE in AWS's Kiro agentic IDE. Hidden text in a web page can make Kiro rewrite its own MCP config fil…

Beware: Claude Code CVE-2026-55607 — A Malicious Repo Can Escape the Sandbox and Execute Code on Your Machine

CVE-2026-55607 is an 8.8-severity sandbox escape in Claude Code that lets a malicious repository chain git worktree naming, symlin…