Skip to content

CVE-2025-61260

CVE

Threat entity extracted from intelligence sources

Frequency
5
occurrences
First Seen
December 2, 2025
Last Seen
May 26, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

AI coding assistants like Claude Code and GitHub Copilot are vulnerable to prompt injection attacks that exploit unvetted external artifacts. These attacks can turn coding assistants into attackers' shells, executing unauthorized commands with developer privileges. Recent vulnerabilities, including...

In 2026, the rise of agentic AI is transforming how businesses operate, particularly in the financial services sector. This new technology allows for autonomous decision-making, which increases the potential impact of errors and security breaches. IT leaders are actively addressing these challenges...

OpenAI has patched a vulnerability in its Codex CLI that could be exploited to execute commands, potentially targeting software developers. The vulnerability is tracked as CVE-2025-61260 and poses risks for those using the affected coding agent.

A command injection vulnerability in OpenAI's Codex CLI has been identified, allowing attackers to execute arbitrary commands on affected systems. This flaw poses a significant risk to users of the Codex CLI, potentially compromising system integrity and security. Details on the specific impact and...

Public Exploits

Checking GitHub for proof-of-concept code…