Fetching from the wire…
Security2026-09-02 · source-backed
Published to NVD September 1, affecting Codex CLI on Windows, macOS and Linux plus Codex Desktop. The command-safety parser read PowerShell's stop-parsing token differently than PowerShell does, so commands got misclassified as safe. An attacker-prepared repository could get Codex to run a file-writing Git command without a prompt, overwrite Codex's own config, and have it launch an attacker-controlled MCP server on next load. Fixed in openai/codex PR #22643 by treating stop-parsing forms as unsupported in the AST-backed flattener. The default filesystem sandbox on macOS and Linux still limited writes, which is a decent argument for leaving it on.
Each link below shares sources, entities, or timing with this story.
Roughly 245 commits, adding session forking, archive/restore from the TUI resume picker, full conversation export to Markdown or clipboard, and Amazon Bedrock Runtime as a built-in provider with AWS profile and region support. Hooks can now run commands asynchronously and invo...
One Claude Code release fixed two independent permission-check bypasses on the same day. That's the story. Version 2.1.221, shipped August 4, patches a Bash tool bypass where zsh could execute hidden commands embedded inside [[ ]] regex conditionals. The approval prompt never...
CVE-2026-55546 at 9.8 sits in verify_math_expression() in QWED-MCP, described by its authors as "a deterministic verification gateway for MCP." It hands the attacker-controlled expression and claimed_result to parse_expr() after normalizing caret syntax, with no global_dict re...
The agent-security topic holds 42 repos above 100 stars, four from large companies rather than startups: NVIDIA/SkillSpector (14,498 stars, scanning Claude Code/Codex/MCP skills for prompt injection), Tencent/AI-Infra-Guard (4,467, red-teaming with Many-Shot/PAIR/GOAT/ActorAtt...
Published to NVD and GitHub Security Advisories on August 27, this is a traversal in read_context in src/index.ts of bsmi021 mcp-file-context-server 1.0.0, remotely exploitable via the path argument, rated 5.5 MEDIUM (NVD). NVD's text notes the project was informed early throu...
Go look at your ~/.claude/CLAUDE.md right now. Mine has internal package names, a build command with a host in it, and notes about which credentials live where. I wrote it assuming exactly one reader. RuntimeWire published traced request captures on August 9 showing Muse Code...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.