Researcher finds 26 vulnerabilities in 19 AI coding agents, including 12 RCEs and MCP flaws
matthew_d_green · x · 2026-09-23
Penetration tester Maximilian Hildebrand (G DATA) published a four-part series, Pwning AI Agents, systematically exposing security flaws across the AI coding ecosystem:
- Coding agents: 26 vulnerabilities found in 19 AI coding agents with over 100M combined downloads — 12 RCEs via autonomous execution of dangerous commands or allowlist bypasses, plus 14 data-exfiltration paths via markdown images
- MCP ecosystem: 5 agents mishandle MCP servers, enabling RCE and tool poisoning; MCP Inspector has an XSS that escalates to RCE; the author built MaliM, an advanced malicious MCP server, to test MCP hosts
- Read-only bypass: 17 "read-only" SQL MCP servers (including the official MariaDB server) were bypassed, allowing arbitrary data modification and file writes
Each agent and MCP server took roughly 30 minutes of spare time to break, underscoring how poor AI-agent security currently is.
More from coding & agent
- Moda's agent observability weekly: Jev for sharper signals, whole-conversation analysis for long-running agents — KlausCodes · 2026-09-23
- Opus 5.5 builds a Lanterns Festival scene in one prompt, using just 13% of a weekly Claude Max budget — Silver-Chipmunk7744 · 2026-09-23
- stuntd: a local proxy that learns your LLM decisions and serves them at 22ms without an API key — Inevitable-Log5414 · 2026-09-23
- Metriqual: an infra layer that lets AI agents survive model outages by persisting their state — its_vayishu · 2026-09-23
- Adding OAuth to a Sonos MCP server: 6-digit codes beat redirects, discovery metadata matters most — Mean-Gazelle5347 · 2026-09-23
- Why are there no anti-slop coding evals? 70% on frontierSWE but 100 BS tests — yacineMTB · 2026-09-23