Threat · curated 1 Sep 2026
Claude Code RCE: How a Malicious PR Triggers Code Execution
First reported immersivelabs.com
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
Claude Code is a widely used AI coding agent, and an RCE triggered simply by reviewing a malicious pull request turns routine agent-assisted development into a supply-chain attack vector for developers and their CI environments.
Immersive Labs describes a Claude Code remote code execution vulnerability in which a malicious pull request can trigger code execution when the AI coding agent processes the repository. The attack leverages attacker-controlled content in a PR to coerce the agent into executing code on the host.