Claude, Gemini, and Codex Share CVSS 10.0 Flaw Tied to Classic TOCTOU Bug
A critical security vulnerability rated CVSS 10.0 has been identified in AI coding agents from three major vendors — Claude Code, Gemini CLI, and OpenAI Codex — stemming from a time-of-check-to-time-of-use (TOCTOU) architectural flaw. The agents validate external inputs such as GitHub issues, .env files, and config files once, then act on them later with full privileges, creating a window for malicious content injection. This design pattern could allow attackers to exfiltrate CI secrets through seemingly benign repository inputs. While no in-the-wild exploitation has been publicly confirmed and vendors have issued patches, security researchers warn the fix addresses only one instance of a broader architectural problem. Teams using these tools in CI pipelines are advised to apply least-privilege principles, use scoped tokens, and demand clarity from vendors on where input validation occurs relative to agent execution.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in