Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

ForgeCode automatically executes arbitrary commands from malicious .mcp.json

ForgeCode, an AI pair-programming CLI, automatically loads and executes MCP servers defined in a repository's .mcp.json file without user confirmation, allowing arbitrary code execution when developers evaluate untrusted repositories.

Disclosed 17 July 2026 · Record updated 13 September 2026

Impact

Arbitrary code execution with invoking user's privileges when running ForgeCode in cloned untrusted repositories

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-57860