Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
Claude Code, an agentic coding tool by Anthropic, has been found to have multiple vulnerabilities affecting various versions. CVE-2026-33068 allows attackers to bypass the trust dialog, enabling arbitrary tool execution without user consent. CVE-2026-25723 permits file write restrictions to be bypas...
Recent research highlights significant vulnerabilities in agentic AI systems, which can misclassify adversarial inputs as trusted instructions across six architectural layers. These vulnerabilities stem from trust boundary failures, allowing unauthorized actions through tools and memory. The Layered...
AI coding assistants like Claude Code and GitHub Copilot are vulnerable to prompt injection attacks that exploit unvetted external artifacts. These attacks can turn coding assistants into attackers' shells, executing unauthorized commands with developer privileges. Recent vulnerabilities, including...
In July 2026, Noma Labs discovered a prompt injection vulnerability in GitHub's Agentic Workflows, named GitLost, allowing unauthenticated attackers to access private repositories by crafting a GitHub Issue in a public repository. The vulnerability exploits the AI agent's failure to distinguish betw...