logo

AI Shopping Assistant Vulnerabilities Enable Remote Code Execution on Retailer’s Servers

ID: e3029535-d96c-5a03-96af-8a852e6cec5e

STIX ID: report--e3029535-d96c-5a03-96af-8a852e6cec5e

Feed Name: GBHackers

Threat Score
72/100

Date Published: 2026-08-31

Date Updated: 2026-09-01

Author: Divya

...
...

Security researchers demonstrated how flaws in a major U.S. retailer's AI shopping assistant (mobile app) allowed them to bypass intent-filtering, obtain hidden inputs, and achieve remote code execution on backend infrastructure; they confirmed live Python execution and access to environment variables and discovered unrestricted Google Maps API keys. The issues were disclosed but reportedly classified by the retailer as intended behavior and remained unresolved after the 90-day disclosure window.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.