logo

More evidence your AI agents can be turned against you

ID: 59b1be4d-abcf-5416-930c-7ee34cbe01b9

STIX ID: report--59b1be4d-abcf-5416-930c-7ee34cbe01b9

Feed Name: CyberScoop

Threat Score
75/100

Date Published: 2025-12-05

Date Updated: 2026-04-21

Author: djohnson

...
...

Aikido researchers disclosed a prompt-injection vulnerability impacting major AI coding assistants integrated into development automation (e.g., GitHub Actions). By embedding commands in repository content (commits, issues, PRs), attackers can cause LLMs to treat that content as instructions, potentially executing shell commands, editing PRs/issues, and leaking privileged GitHub tokens; vendors have been notified and some fixes applied, but the root cause is architectural and may affect many projects.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.