AI Coding Assistants Face Critical Security Risks: RCE and Supply Chain Attacks
Three AI coding agents, three critical RCEs — and the same trust-boundary bug in all of them
Security researchers just dropped a coordinated disclosure of critical AI coding assistant vulnerabilities affecting Claude Code, Gemini CLI, and OpenAI Codex — the three most widely deployed agentic coding workflows shipping in production today. An attacker-controlled issue or zero-privilege input can breach the trust boundaries of the agent "harness" — the permissions, tools, sandbox, filesystem, and automation wrapped around the model — and walk away with code execution, stolen secrets, or a fully compromised developer workflow.
This isn't a vendor-bashing post.
This is an excerpt. Read the full post at otf-kit.dev/blog/ai-coding-security-risks — full-stack kits your AI coding agent can actually ship to production. Browse the kits →
