Findings/injection-reaches-code-execution

In several agent frameworks and coding tools, prompt injection in content the agent read reached code execution on the host, sometimes combined with a common setting such as an allowlisted command.

Corroboratedmeasured5 evidence records from 5 independent sourcesassistant-drafted
Scope: what this does not show

Affected versions of named products, some only under specific configurations (an allowlisted benign command in Gemini CLI; particular Semantic Kernel plugins exposed to the model). Most were patched after disclosure, but OX reports some MCP-related projects unpatched or rejected as by design. None is reported as exploited in the wild.

Corroborated: Supported by at least two independent sources.

Evidence

Key questions that rely on this finding

Status history

  1. 2025-07-28ReportedGemini CLI executed commands the approval display did not show. · record
  2. 2025-08-01CorroboratedCursor CVE: injected content could create files that executed code. · record