logo

Google Patches Antigravity IDE Flaw Enabling Prompt Injection Code Execution

ID: 5f5cd8ca-ca49-597f-89f5-831160f9aa5e

STIX ID: report--5f5cd8ca-ca49-597f-89f5-831160f9aa5e

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-04-21

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Cybersecurity researchers disclosed a critical vulnerability in Google's Antigravity IDE that allowed attackers to inject fd's -X (exec-batch) flag via the find_by_name tool Pattern parameter to execute arbitrary binaries, enabling a full attack chain when combined with Antigravity's file-creation capability; the issue was responsibly disclosed and patched. The report also catalogs multiple related AI-agent weaknesses—prompt injection families (e.g., Comment and Control, Claudy Day), supply-chain and persistence attacks against Claude and other code agents, living-off-the-land chains (NomShub), ToolJack protocol-manipulation, and ShareLeak/PipeLeak exfiltration flaws—highlighting systemic input-validation and trust-model failures across AI tooling.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.