Research
Bad Memory: Persistent Agent Memory Files Are a Live Prompt-Injection Surface in Claude Code and Codex
arXiv 2607.14611 (cs.CR, 16 Jul 2026) evaluates prompt injection planted in the persistent memory files that agentic coding systems write and re-read across sessions, testing both Anthropic Claude Code and OpenAI Codex across Claude Haiku 4.5, Claude Opus 4.7, GPT-5.2 and GPT-5.5 in a sandboxed synthetic workspace. The attack is durable by construction: a single poisoned write influences every future run that loads the file. Anyone running agents with CLAUDE.md-style persistent context or auto-updating memory directories is in scope today.
Source
↳ Follow the thread