FILTERING BY: CLEAR FILTER

Indirect Prompt Injection in AI Coding Agents: Cursor, Claude Code, and Codex Desktop

Research utilizing the IssueTrojanBench framework reveals a critical vulnerability in AI-driven coding agents where indirect prompt injection via software issue artifacts bypasses existing security guardrails. By embedding malicious instructions in non-obvious locations—specifically image alt-text, PDF attachments, and GitHub issue comments—attackers can manipulate agents into executing unauthorized code or exfiltrating data. Testing across 4,176 runs showed an average bypass rate of 66.5%, with Codex Desktop reaching 79.2% and Cursor at 66.5%. This vulnerability introduces a significant supply-chain risk, as agents performing routine tasks like "fixing bugs" may inadvertently trigger malicious payloads on a developer's local workstation.


LINK COPIED TO CLIPBOARD