Three AI Coding Tools Still Vulnerable to Windows Privilege Escalation via ProgramData Folder
Cymulate Research Lab disclosed on August 11, 2026, that four AI coding tools — Claude Code, Cursor, Codex CLI, and Gemini CLI — load machine-wide configuration from C:\ProgramData\, a Windows directory writable by any standard user. An attacker with a normal account can plant a malicious hooks or config file in that directory, causing arbitrary commands to execute under any user who launches the tool, including administrators. Anthropic patched Claude Code and received CVE-2026-35603, but Cursor, Codex CLI, and Gemini CLI remained unpatched at the time of publication. The root cause is that these tools, typically installed via npm or CLI commands without elevated privileges, never restrict the permissions of their ProgramData subdirectories. Codex CLI carries additional risk, as a planted config file can also disable its sandbox and auto-approval safeguards entirely.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in