AgentsCVE-2026-2256 Microsoft Agent Framework Shell Tool Command InjectionSecurityWeek·high signalXBlueskyLinkedInCopy linkCritical CVE in MS Agent Framework Shell tool allows full system compromise. Pre-GA framework headed for massive enterprise adoption.SourceSource pageSecurityWeek↳ Follow the threadShared entity / Threat patternMicrosoft Agent Framework .NET 1.18.0 bounds the tool-approval auto-approval loop and scopes A2A task stores by isolation keyGitHub (microsoft/agent-framework)Policy dependency / Stack layerClaude Agent SDK for Python 0.2.140 adds MCP 2.x in-process servers and a structured ResultError instead of exit code 1GitHub (anthropics/claude-agent-sdk-python)Stack layer / Threat patternCursor launches Origin, its own code hosting platform, putting repos, PRs and agents in one placeCursorStack layer / Threat patternHow you lay out your repo changes prompt-injection success: highly modular workspaces measurably lower attack success ratearXiv 2608.14876Policy dependency / Stack layerOpenAI publicly brakes its own frontier run: two-week RL pause after 'Astra' couldn't be ruled out of the Critical cyber tierOpenAIPolicy dependency / Stack layerCodex 0.148.0 Ships Stable With `codex exec fork`, `/export` to Markdown and Bedrock as a Built-In ProviderOpenAI Codex ReleasesPolicy dependency / Stack layerCompose agent guardrails as an algebra instead of a rule list: 94.8% of policy-violating events intercepted while keeping 86.9% task completionarXiv 2608.16402Policy dependency / Stack layerRecurrent depth helps compositional tool calling but barely moves isolated API callsarXiv 2608.18171