Fetching from the wire…
Security2026-09-01 · source-backed
Theia 1.73.0 through 1.74.x resolved paths from writeFileContent, suggestFileContent and their helpers with no workspace-containment check, so a model-supplied ../.bashrc, absolute path or tilde-expanded path wrote or deleted files as the Theia backend user (NVD). The path argument comes from model output, so indirect prompt injection steers it, and Agent Mode applies writes without a per-file prompt. Upgrade to 1.75.0. Same class as the Hermes auth.json overwrite two days earlier, which suggests agent file tools are still shipping without containment as the default posture.
Each link below shares sources, entities, or timing with this story.
Your llms.txt is a config file for other people's agents. That's the part most teams publishing one didn't think through. A study published August 27 scanned 6,214 live domains belonging to defense contractors, Fortune 500 companies and Big Tech, and found 227 install commands...
A category has formed around one job, watching and steering many concurrent coding agents from a single pane. AionUi (TypeScript) markets a 24/7 "Cowork" app spanning OpenClaw, Hermes, Claude Code, Codex, OpenCode and 20+ more CLI agents; agent-of-empires (Rust) offers TUI and...
A10 Networks made its AI Gateway generally available on August 14, pitched as a "centralized control plane for unified routing, cost management, and governance across every AI agent, application and large language model" (Help Net Security). SelectHub launched DataGrout the sa...
Announced August 7: Hermes can use AI Gateway as its inference layer for 200+ models with no token markup and per-request dashboard visibility, and execute shell commands inside an isolated Vercel Sandbox microVM instead of on your machine, with Node.js 24/22 and Python 3.13 a...
AionUi is at 31,043 stars fronting OpenClaw, Hermes Agent, Claude Code, Codex, OpenCode, Gemini CLI, and 20+ others behind one customizable UI, and VibeAround pitches the same thing across web, mobile, and messaging. Session management, cross-agent handoff, and always-on avail...
CVE-2026-82020, published August 28 at 6.8, let an attacker who could influence ingested message content direct the agent's file-write tooling to overwrite auth.json, because the guard list excluded that exact file and no path warning fired. Fixed in 0.17.0. (NVD) A deny-list...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.