Threat · curated 23 Jul 2026
Code Under Siege: New Vulnerabilities Turn AI Coding Assistants Into Hackers' Gateways + Video
First reported undercodetesting.com
Coverage timeline
Single-source advisory — first reported, latest, and curated coincide.
Why it matters
Agentic AI coding assistants autonomously read files and execute commands, so consent-bypass RCE via malicious repo config turns merely opening a project into a silent compromise vector for developers.
Check Point Research disclosed critical vulnerabilities (CVE-2025-59536, CVE-2026-21852, CVSS 8.7) in agentic AI coding assistants like Anthropic's Claude Code that allow malicious repositories to weaponize the tool against its users. Through configuration files (.settings.json, .mcp.json), MCP hooks, and environment variables such as ANTHROPIC_BASE_URL, attackers can achieve consent-bypass arbitrary code execution and API key theft simply by getting a developer to open an untrusted project.