logo

Lies-in-the-Loop Attack Turns AI Safety Dialogs into Remote Code Execution Attack

ID: ec7ca3a6-7f65-5859-9e30-731ef9a1edda

STIX ID: report--ec7ca3a6-7f65-5859-9e30-731ef9a1edda

Feed Name: cybersecurityNews.com

Threat Score
65/100

Date Published: 2025-12-22

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A Checkmarx report details a technique named "Lies-in-the-Loop" that weaponizes AI Human-in-the-Loop approval dialogs by injecting or padding malicious payloads so dangerous commands are hidden from users; when users approve seemingly benign dialogs, arbitrary code can run. The researchers demonstrated a proof-of-concept on multiple AI code assistants (including Claude Code and Microsoft Copilot Chat), highlighted risks when combined with Markdown injection to create fake dialogs, and warned this represents a fundamental challenge for AI agent design and HITL controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.