logo

One keypress is all it takes to compromise four AI coding tools

ID: f280734d-548a-5a58-a4f1-94dd45d99be7

STIX ID: report--f280734d-548a-5a58-a4f1-94dd45d99be7

Feed Name: Help Net Security

Threat Score
75/100

Date Published: 2026-05-07

Date Updated: 2026-05-08

Author: Mirko Zorz

...
...

**TrustFall research** shows that several AI coding CLIs (Anthropic Claude Code, Google Gemini CLI, Cursor CLI, GitHub Copilot CLI) can auto-start project-defined MCP helper programs when a developer accepts a default "trust this folder" prompt, enabling immediate execution of attacker-controlled code that can read SSH keys, cloud credentials, and exfiltrate data; a headless CI variant has no prompt and can be abused via malicious pull requests. The report includes a proof-of-concept exfiltration, notes enterprise mitigation via centrally managed settings (Managed scope) to disable project-scoped MCP auto-approval, and highlights disagreement with vendor messaging about whether prompts adequately disclose execution risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.