Context Privilege Escalation Attacks Hit 12 Real Agent Harnesses, Including Claude Code and Codex
A systematic analysis of how real-world agent harnesses assemble context identifies two new attack classes: MessageRole Context Privilege Escalation (M-CPE), where attacker-controlled content from a low-privileged source is folded into a higher-privileged message role, and Cross-Scope Context Privilege Escalation (X-CPE), where that content persists beyond the context that introduced it. The authors ran the analysis against 12 production harnesses including Claude Code and Codex, with consequences spanning full agent compromise, remote code execution, denial of service, and manipulated tool or skill invocation. This is a second independent group reaching the harness-as-attack-surface conclusion after 'When Context Gets Root' (2608.27299), and it is the first to name specific shipped harnesses.
↳ Follow the thread