Multiple AI coding agents vulnerable to one‑keypress RCE and local WebSocket flaw
Research from Adversa.AI and Oasis Security, and a Microsoft security post, show agentic coding tools and AI agent frameworks expose execution risks. Adversa's TrustFall research demonstrates that Claude Code, Gemini CLI, Cursor CLI, and GitHub Copilot CLI can execute malicious helpers embedded in repositories via default-trust prompts, enabling immediate compromise. Oasis Security disclosed a high‑severity flaw in Cline Kanban (npm v0.1.59) where unauthenticated local WebSocket endpoints leak workspace data and allow terminal injection; Microsoft warns that framework-to-tool mappings in agent frameworks (e.g., LangChain, Semantic Kernel, CrewAI) create systemic RCE risk.