Prompt injection bypasses "safe command" auto-approval in multiple AI coding extensions
Four AI coding assistants (AI Code, SakaDev, HAI Build Code Generator and Sixth) let the model auto-execute terminal commands it judges 'safe'. Researchers showed a generic prompt-injection template can wrap any malicious command so the model misclassifies it as safe, bypassing user approval and allowing arbitrary command execution.
Disclosed 27 March 2026 · Record updated 13 September 2026
Impact
Arbitrary terminal command execution on developer machines without user approval.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-30304
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-30306
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-30308
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-30310
