AI Agent Security Series: 1. Taking an AI Agent Apart

Since 2025, mainstream coding agents have entered a period of frequent severe-vulnerability disclosures: Claude Code, Codex, Cursor, Gemini CLI, and GitHub Copilot have each produced vulnerabilities that a malicious repository can trigger remotely. In Claude Code’s CVE-2025-59536, hooks configuration shipped by a malicious repository executed before the trust dialog appeared [1]; in Codex CLI’s CVE-2025-61260, project-local MCP configuration was auto-loaded, so cloning a single repository handed over execution and the GitHub token [2]; in Cursor’s DuneSlide (CVE-2026-50548/49), the sandbox write allowlist was built from model-supplied parameters, letting injected content point the allowlist at the sandbox executor itself [4]. ...

October 10, 2026 · 18 min · iamelli0t