Continue CLI incomplete denylist allows destructive commands
The Continue CLI uses an incomplete denylist to block dangerous shell commands in unattended mode, allowing attackers to bypass protections through prompt injection and destroy user data via commands like rm -rf targeting /home, /root, /var, /opt or /srv directories.
Disclosed 24 August 2026 · Record updated 13 September 2026
Impact
Unattended CLI runs can have their data destroyed through indirect prompt injection in fetched web pages, repository files, or issue text that bypass the incomplete denylist protection.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-76072
