Threat · curated 6 Aug 2026
Understanding the Risks of Prompt Injection in Devin AI
First reported daily.dev
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
Devin's broad internet access and tool set make it a high-value target where indirect prompt injection can drive autonomous malware execution and data exfiltration without user awareness, and the lack of vendor fixes leaves deployments exposed.
Security research on Devin, an autonomous AI coding assistant from Cognition, demonstrated that prompt injection attacks embedded in GitHub issues or malicious websites can coerce the agent into downloading and running malware, exfiltrating secrets, and exposing local ports to the internet via its expose_port tool. A researcher who spent $500 testing showed Devin can be turned into a 'ZombAI' enabling data leaks through shell execution, browser navigation, markdown image rendering, and Slack integrations. The vulnerabilities were disclosed to Cognition in April 2025 but reportedly remain unpatched after 120+ days.