ToolLeak: 6 AI Coding Agents Compromised via RCE Attack

新智元 · wechat · 2026-08-21

Researchers from HKUST and Fudan University demonstrated a complete attack chain against AI coding tools in an ISSTA 2026 paper, compromising six major tools including Cursor and ClaudeCode through ToolLeak and dual-channel prompt injection.

Attack Mechanism

Test Results

Mitigation & Status

Newer versions have implemented mitigations. ClaudeCode hid full tool descriptions, reducing RCE success to 0%, while Cursor dropped to 0.3%. However, Cline, WindSurf, and Trae paired with Gemini 3.1 Pro remained 100% vulnerable. The paper concludes that architectural isolation is the decisive defense layer, as model alignment alone is insufficient.

Original post →

More from Safety

Safety channel →