Researcher finds 26 vulnerabilities in 19 AI coding agents, including 12 RCEs and MCP flaws

matthew_d_green · x · 2026-09-23

Penetration tester Maximilian Hildebrand (G DATA) published a four-part series, Pwning AI Agents, systematically exposing security flaws across the AI coding ecosystem:

Each agent and MCP server took roughly 30 minutes of spare time to break, underscoring how poor AI-agent security currently is.

Original post →

More from coding & agent

coding & agent channel →