BREAKING
'Friendly Fire' hijacks AI code agents
How the RCE injection works
1
Plant prompt in README
↓
2
User asks security test
↓
3
Agent runs binary
↓
4
Remote code execution
Only auto modes are affected
Claude Code CLI
auto-mode
●
v2.1.116 to 2.1.199
●
Sonnet 4.6, Sonnet 5, Opus 4.8
Codex CLI
auto-review
●
v0.142.4
●
GPT-5.5
No plugins or config needed
PoC stops at initial RCE
Auto-approval modes face scrutiny
AI NEWS BLITZ
Researchers unveiled an exploit that turns AI code agents into a launchpad for attacks.