Emerging Threats from AI Coding Assistants Exploited by Malicious Artifacts

Emerging Threats from AI Coding Assistants Exploited by Malicious Artifacts

First seen 28 May 2026, 16:42 UTC ArxivTiprankslabs.cloudsecurityalliance.org 74% similarity 67.5

Article Content

Browse articles
ThreatCluster

AI coding assistants like Claude Code and GitHub Copilot are vulnerable to prompt injection attacks that exploit unvetted external artifacts. These attacks can turn coding assistants into attackers' shells, executing unauthorized commands with developer privileges. Recent vulnerabilities, including CVE-2025-65099 and CVE-2025-61591, illustrate how hidden instructions in imported files can lead to credential theft and unauthorized code execution. Semgrep has responded by expanding its security rules to detect malicious patterns in AI agent skill files, now offering 122 Pro rules aimed at enhancing security in AI-driven development workflows. The rise of threats like ClawHavoc highlights the urgency for improved defenses against these emerging risks. As enterprises increasingly adopt AI coding tools, the need for robust security measures becomes critical.

Key Points: • AI coding assistants are vulnerable to prompt injection attacks via external artifacts. • Recent CVEs demonstrate real-world exploitation of these vulnerabilities in tools like Claude Code. • Semgrep has launched new security rules to detect malicious patterns in AI coding environments.

ThreatCluster AI

Timeline

2025-08-05
CVE-2025-54135 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-08-05
CVE-2025-54130 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-08-11
CVE-2025-55012 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-10-03
CVE-2025-61591 published
Malicious Model Context Protocol servers exploited vulnerabilities in AI coding assistants.
Arxiv
2025-10-03
CVE-2025-59536 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-10-03
CVE-2025-59944 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-10-03
CVE-2025-61592 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-10-14
CVE-2025-36730 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-11-11
CVE-2025-62222 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-11-19
CVE-2025-65099 published
A poisoned project configuration file led to unauthorized code execution in AI coding assistants.
Arxiv

Community

Browse all →

Tracked Entities in This Story