Vulnerabilities · 130 days ago
Two separate disclosures show AI coding assistants and local developer servers can be abused: Claude Code's default-trust agent behavior enables repo-based RCE, while Cline Kanban v0.1.59 exposes local WebSocket endpoints to cross-origin attacks.
6 sources covering this story
Pen tests show AI security flaws far more severe than legacy software bugs
Penetration tests of AI systems expose significantly higher severe-flaw density when compared to legacy apps. New attack surfaces, larger blast radii, and unclear remediation ownership compound the risks.
Anthropic response to 1-click pwn: Shouldn't have clicked 'ok'
Security biz Adversa AI argues users of AI tools need clearer warnings
When prompts become shells: RCE vulnerabilities in AI agent frameworks | Microsoft Security Blog
Learn how these vulnerabilities work, what’s impacted, and how to secure your agents.
Cline Kanban Flaw Lets Websites Hijack AI Coding Agents
Oasis Security finds critical Cline kanban WebSocket flaw exposing AI coding agents to hijack
One keypress is all it takes to compromise four AI coding tools - Help Net Security
Adversa AI's TrustFall research reveals an AI coding CLI vulnerability letting cloned repos run code on developer machines with one keypress.
AI Coding Agents Could Fuel Next Supply Chain Crisis
“TrustFall” attack shows how AI coding agents can be manipulated into launching stealthy supply chain compromises.
Part of the PlainSec briefing for 2026-05-07