A recurring vulnerability across AI coding platforms from Anthropic, Google, and OpenAI that enables attackers to remotely execute commands, steal API keys, and compromise software supply chains without requiring any privileged access This article explores recurring vulnerability ai. . The flaw was identified by Novee security researcher Elad Meged while testing each vendor’s default configurations on their own public repositories, indicating the exposure is not theoretical; it exists in live code used by millions of developers today.
Researcher Elad Meged discovered that a single GitHub issue opened by an anonymous user with no privileges could trigger the agent and inject prompt-injection payloads into the harness, which failed to properly contain them.
Combining full shell access with easily readable credentials let attackers escalate from a single anonymous issue to pushing malicious code directly into the main branch, a compromise Google rated CVSS 10.0 in its own security advisory and addressed by breaking change to its headless execution trust model. OpenAI swiftly isolated these processes within three days by separating them into distinct jobs but warns that this pattern remains widely adopted elsewhere. The experts advise viewing all files generated during workflows and each workflow itself as potentially unverified inputs, instead of presuming default settings from vendors to be inherently secure.
Enhance your Security Operations Center (SOC) by accelerating threat detection and swift investigations.












