Google Patches Antigravity IDE Flaw Enabling Prompt Injection Code Execution
ID: 5f5cd8ca-ca49-597f-89f5-831160f9aa5e
STIX ID: report--5f5cd8ca-ca49-597f-89f5-831160f9aa5e
Feed Name: The Hacker News
Cybersecurity researchers disclosed a critical vulnerability in Google's Antigravity IDE that allowed attackers to inject fd's -X (exec-batch) flag via the find_by_name tool Pattern parameter to execute arbitrary binaries, enabling a full attack chain when combined with Antigravity's file-creation capability; the issue was responsibly disclosed and patched. The report also catalogs multiple related AI-agent weaknesses—prompt injection families (e.g., Comment and Control, Claudy Day), supply-chain and persistence attacks against Claude and other code agents, living-off-the-land chains (NomShub), ToolJack protocol-manipulation, and ShareLeak/PipeLeak exfiltration flaws—highlighting systemic input-validation and trust-model failures across AI tooling.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
