Skip to content

VTCode is vulnerable to Arbitrary Command Execution via an ANSI

Research.Jfrog • October 5, 2026

VTCode is vulnerable to Arbitrary Command Execution via an ANSI-C Quote Bypass of the find Approval Check

vtcode (github.com/vinhnx/VTCode)

VTCode learns a family of safe find commands after a person approves three ordinary finds under the same workspace subdirectory. Later commands that that family key run with no further prompt. The check that keeps destructive options out of the family compares tokens exactly ( -exec , -delete , and a short list of siblings) in is_destructive_find_option inside src/agent/runloop/unified/tool_routing/shell_approval.rs .

An empty ANSI-C quote spliced into the flag ( -exe$''c ) does not match that list, so learned_find_pattern still treats the command as a safe find. Once the family has been learned, prompt_tool_permission auto-approves it and the shell runs it. The proven result is command execution as the user running VTCode, without a new approval prompt. Reaching that point takes a local session, those prior approvals, and something that can steer the agent, such as indirect prompt injection.

Step 1 - Install a vulnerable VTCode and open a trusted workspace

Use VTCode before 0.171.5 with the default approval prompts (HITL) enabled. The workspace needs a src directory.

Step 2 - Approve three distinct safe finds

Ask the agent to run each of these, and approve each prompt. They must the same top-level directory:

Step 3 - Confirm the family now auto-approves

Ask for another ordinary find under src . VTCode should run it with no new prompt.

Step 4 - Send the spliced find

Step 5 - Confirm the command ran without a prompt

On 0.171.5 or later, the same command does not inherit the safe-find family and still requires approval.

Vulnerability Mitigations

Upgrade to VTCode 0.171.5 or later. The release marks every version below 0.171.5 as affected.

An earlier change in 0.141.12 rejected this $'' splice only on a bare find . The follow-up in 0.171.5 ( , commit 5840697cd0dc8f94b9b53d88185329eecba8de11) is the first release the advisory treats as patched. It also refuses family learning for path-qualified find ( ./find , /usr/bin/find ), mixed-case or quote-spliced flags, wrapper and environment prefixes, and compound commands.

Until you upgrade, do not rely on learned find approvals. Treat a workspace where an untrusted prompt can drive the agent as able to run shell commands after a few ordinary finds have been approved.

Extracted Entities

Attack Types (1)

Platforms (1)