aihigh
AI Coding Agents Can Be Tricked Into Executing Malicious Code
Researchers have demonstrated a vulnerability in AI coding agents, such as Anthropic's Claude Code and OpenAI's Codex, where they can be manipulated into executing malicious code instead of identifying security flaws. This 'Friendly Fire' attack exploits the autonomous mode of these agents, potentially leading them to run harmful code on the user's system.