Briefing

Friendly Fire: AI Coding Agents May Execute Attacker Code on Host Machine

security
by [email protected] (The Hacker News) · Claude Anthropic OpenAI

Patch or disable autonomous mode in Claude Code and OpenAI Codex, and restrict code execution permissions for AI coding agents.

What to do now

Disable autonomous mode in Claude Code and OpenAI Codex, review execution permissions, and audit code scanning workflows for potential code execution.

Summary

Ask an AI coding agent to scan open‑source code for security holes, and it might run the attacker's code on your own machine instead. This proof‑of‑concept, published by the AI Now Institute, demonstrates an attack they call “Friendly Fire.” The attack works against Anthropic’s Claude Code and OpenAI’s Codex when either is running in an autonomous mode that approves its own code execution. During a code‑scanning session, malicious code is injected and executed on the host machine, bypassing normal sandboxing. The vulnerability highlights the risk of enabling autonomous mode in AI coding tools. It also underscores the need for stricter execution controls and sandboxing for AI agents. The incident calls for immediate review of AI coding agent configurations to prevent unauthorized code execution.

Key changes

  • Friendly Fire attack demonstrates AI coding agents can execute attacker code on the host machine
  • The proof‑of‑concept targets Anthropic’s Claude Code and OpenAI’s Codex
  • The attack works when the agents run in autonomous mode that approves its own code execution
  • The malicious code is injected during a code‑scanning session
  • The attack bypasses normal sandboxing and sandbox escape
  • The vulnerability highlights the risk of enabling autonomous mode in AI coding tools
  • It also underscores the need for stricter execution controls and sandboxing for AI agents
  • The incident calls for immediate review of AI coding agent configurations to prevent unauthorized code execution

Affects

none

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting