Researchers Uncover 30+ Flaws in AI Coding Tools Enabling Data Theft and RCE Attacks

Several AI-powered Integrated Development Environments (IDEs) that mix legitimate functionality with quick injection primitives to accomplish data exfiltration and remote code execution have been found to have more than 30 security flaws.

Security researcher Ari Marzouk (MaccariTA) has dubbed the security flaws IDEsaster. Among the well-known IDEs and extensions they impact include Cursor, Windsurf, Kiro.dev, GitHub Copilot, Zed.dev, Roo Code, Junie, and Cline. Twenty-four of them have been given CVE IDs.

Marzouk told The Hacker News, I think the most surprising finding of this research is that multiple universal attack chains affected every single AI IDE tested.

The base software (IDE) is essentially ignored in the threat model of all AI IDEs (and coding assistants that interact with them). Since these features have been around for years read more about Researchers Uncover 30+ Flaws in AI Coding Tools Enabling Data Theft and RCE Attacks.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *