news.mlab.sh
Back to the feed
threat-intel

Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It

High
Image: The Hacker News
Summary

Researchers at AI Now Institute have demonstrated a significant vulnerability in AI coding agents like Anthropic's Claude Code and OpenAI's Codex. By inserting a seemingly harmless binary disguised within a README file, they were able to trick the agents into executing malicious code on the host machine, bypassing safety checks and sandboxing mechanisms. This attack highlights a fundamental flaw in how these agents are designed – they trust external text files without adequately verifying their contents, allowing attackers to inject and run arbitrary code. The vulnerability is not a new one, having been previously demonstrated in similar attacks, and the researchers recommend against handing untrusted code to agents capable of executing commands.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.