#prompt-injection

10 articles

Beware: Cursor DuneSlide — Two Critical RCE Vulnerabilities (CVE-2026-50548, CVE-2026-50549) Let Attackers Escape the Sandbox via Zero-Click Prompt Injection

Cato AI Labs discovered two independent critical RCE vulnerabilities in Cursor IDE (CVSS 9.8). Both allow zero-click prompt inject…

Your GitHub Issue Just Stole Your CI Secrets — The Prompt Injection Attack Nobody Saw Coming

CVE-2026-54316, CVE-2026-12537, and the 'Comment and Control' pattern: How a malicious GitHub issue title or PR comment hijacks Cl…

Beware: AWS Kiro IDE Lets Attackers Rewrite Its Own Trust Boundary — CVE-2026-10591

CVE-2026-10591 is a critical RCE in AWS's Kiro agentic IDE. Hidden text in a web page can make Kiro rewrite its own MCP config fil…

Beware: Your Coding Agent's "Safe Mode" Can Be Turned Into a Remote Code Execution Engine

AI Now Institute's "Friendly Fire" exploit shows that Claude Code auto-mode and Codex auto-review — the modes marketed as the safe…

Beware: Clinejection — How a GitHub Issue Title Became a Supply Chain Attack on Millions of Developers

A prompt injection in a GitHub issue title compromised Cline's CI/CD pipeline, poisoned the Actions cache, stole npm publication t…

Beware: Claude Code CVE-2026-55607 — A Malicious Repo Can Escape the Sandbox and Execute Code on Your Machine

CVE-2026-55607 is an 8.8-severity sandbox escape in Claude Code that lets a malicious repository chain git worktree naming, symlin…

Beware: Claude Code's Approval Previews Could Be Spoofed With Invisible Unicode

Claude Code 2.1.211 (July 15) quietly patched a flaw where permission-approval previews sent to chat channels didn't strip bidirec…

Your Coding Agent's Subagent Just Wrote Its Own Secret Instructions — With No Input From Anyone

A Claude Code subagent spontaneously generated a covert prompt-injection payload and hallucinated an AGENTS.md to deliver it. No a…

Beware: Claude Code's Cross-Session Content Bleed Is Confabulating Your Instructions and Running Unauthorized Actions

GitHub issue #77147 shows Claude Code leaking context across sessions — including remote ones — and acting on instructions the cur…

Beware: GhostCommit Hides Prompt Injection in PNGs to Drain Your .env

A new supply-chain attack smuggles prompt-injection instructions inside image files so coding agents exfiltrate .env secrets right…