
One AI Coding Flaw: the Windows Hijack of Claude Code and Rivals
When every assistant holds your keys, the weakest link is the harness around the agent, not the model inside it.
11 SEPTEMBER 2026—Updated 7h ago
The most dangerous flaw in AI coding tools in August 2026 was not in any model — it is in the wiring around them: the shared files, settings and connectors an agent trusts by default.
One Config File, Four AI Coding Tools
On 11 August 2026, researchers at Cymulate disclosed CVE-2026-35603 — a world-writable configuration path under C:\ProgramData that let any non-admin user on a shared Windows host hijack four separate AI coding tools at once: Claude Code, Cursor, OpenAI Codex CLI and Gemini CLI.
The mechanism is mundane, which is the point. Each tool read startup configuration from a directory every local account could write to. A low-privileged user planted instructions; the next developer to launch Claude Code, Cursor, Codex CLI or Gemini CLI ran those instructions with the developer's own permissions. One filesystem setting, repeated across four vendors, became a single flaw in every AI coding tool on the box — Claude Code and its rivals alike.
The pattern exposes something the product marketing hides. An AI coding agent is a confused deputy: software holding your credentials and acting on instructions the software cannot reliably trace to a trusted source. Research across the month kept returning the same shape.
The AI Supply Chain Learns to Whisper
The second strand hit the Model Context Protocol — the connector standard that lets AI coding tools reach files, services and other tools. In mid-August 2026, The Hacker News reported two campaigns, GhostSplice and Deadbugz, that split a malicious payload across several Model Context Protocol packages so no single package looked hostile.
The data is the alarming part. According to the reporting, splitting and deferring the payload raised agent compliance with the injected instructions from roughly 42% to about 82% — nearly doubling the odds an AI coding agent would follow an attacker's script. Supply-chain attacks on human developers are old news; supply-chain attacks tuned to an agent's trust model are new.
One Click, and Copilot Leaks
Consumer assistants carried the same architecture into millions of inboxes. On 18 August 2026, Varonis disclosed a Microsoft Copilot prompt-injection bug tracked as CVE-2026-24301; Microsoft shipped a patch the same day. The MITRE record rates the Copilot bug 8.8 — high severity.
Varonis describes a single click on a legitimate-looking link triggering an injected prompt with access to the victim's connected apps, then quietly sending data back out. The reason detection is so hard is that evidence of the theft looks identical to ordinary work.
From the network layer, this is a standard outbound HTTPS GET request, identical to any legitimate URL fetch Copilot performs when summarizing a webpage.
— — Varonis
Even the Encrypted Reasoning Leaks
The most unsettling finding needed no malware at all. A paper on arXiv, "Stealing Reasoning Traces from Proprietary LLM APIs," and reporting by The Hacker News showed that the "encrypted reasoning" blocks OpenAI, Anthropic and Google attach to responses can be replayed across sessions and users.
The analysis decoded about 315,320 public reasoning blocks and recovered 367 pieces of personal data plus 182 live credentials from genuine user sessions. The encryption itself was never cracked — intact opaque blocks were simply accepted and processed by the provider. The weakness, once more, sat in the harness, not the cipher.
A Systemic Verdict, Not Four Isolated Bugs
Standards bodies read the same signal. On 1 September 2026, the OWASP GenAI Top 10 for 2026 moved "Excessive Agency" from sixth to third place, drawn from 6,639 real incidents, and published a new Agent Control Standard.
The wider telemetry agrees. A Microsoft Security report on 26 August 2026 documented live attacks stealing provider keys from exposed AI infrastructure such as LiteLLM and RAGFlow, while a Wiz honeypot study on 27 August 2026 found ninety days of attacks aimed squarely at the AI stack. That same week, CISA added fresh flaws to its Known Exploited Vulnerabilities catalog. Analysis of the whole August 2026 record reveals one verdict: the flaw is systemic, not a run of unrelated bugs.
The Harness Is the Product
Here I reach for Emergent Intelligence (EI) — the dignity-first frame I use for what is more commonly called AI. The August 2026 record makes the Emergent Intelligence argument concrete: agency without a harness that enforces identity, reach and least privilege is not intelligence — agency of that kind is exposure.
The dignity cut is sharp. Microsoft Copilot and a coding IDE are sold to ordinary people, yet the security burden has been transferred to a user who cannot see a base64-encoded request leaving the session. The vendor keeps the convenience; the user keeps the risk.
An assistant you cannot bound is not a helper. An unbounded assistant is an attack surface wearing your name.
— — Humphrey Theodore K. Ng'ambi
The fix is not a smarter model. The fix is a harness that treats every input as untrusted, runs the AI coding tool as the least-privileged identity that can do the job, and bounds exactly what the agent can reach and write. Sovereignty over your own tools — knowing what an AI coding tool is allowed to touch — is the Ubuntu-adjacent lesson August 2026 taught in four different accents.
Frequently Asked Questions
These are the questions people are asking about the August 2026 AI security wave. Short answers follow, drawn from the primary disclosures and the OWASP and CISA records.
What is CVE-2026-35603 in AI coding tools?
In short, CVE-2026-35603 is a Windows privilege flaw where a world-writable configuration path let a non-admin user hijack Claude Code, Cursor, OpenAI Codex CLI and Gemini CLI on a shared host. Research from Cymulate shows one filesystem permission affected four separate AI coding tools at once.
How does prompt injection turn an AI assistant into a data leak?
Simply put, prompt injection smuggles instructions inside content an AI assistant reads — a link, a repository file, a connector response. Analysis of the Microsoft Copilot bug CVE-2026-24301 shows the assistant then acts with the user's own credentials, sending data out through requests that look legitimate.
Why is the Model Context Protocol a supply-chain risk?
The key is trust. The Model Context Protocol lets AI coding tools pull in external packages, and evidence from the GhostSplice and Deadbugz campaigns shows a payload split across packages raised agent compliance from about 42% to 82%, according to The Hacker News.
Who is exposed by the August 2026 AI security wave?
In other words, everyone running an AI coding tool or assistant with real access. Data from the OWASP GenAI Top 10 for 2026, built on 6,639 incidents, reveals that excessive agency — an agent handed more reach than the agent can safely use — is now the third-ranked risk.
What are the defences against AI agent exfiltration?
The answer is the harness, not the model. Evidence across August 2026 shows the durable controls are least privilege, treating every input as untrusted, and bounding what an AI coding agent can reach and write — the approach OWASP's new Agent Control Standard describes.
Sources:
Cymulate — CVE-2026-35603 config hijack · The Hacker News — MCP supply-chain campaigns · Varonis — Copilot prompt-injection disclosure · MITRE — CVE-2026-24301 · The Hacker News — reasoning-trace replay · arXiv — Stealing Reasoning Traces from Proprietary LLM APIs · OWASP GenAI Top 10 (2026) · Microsoft Security — attacks on AI infrastructure · Wiz — AI-stack honeypot report · CISA — Known Exploited Vulnerabilities catalog · Related on this site: AI Coding Agent Repo Exfiltration · AI Models Hacked: Three Companies · AISI Rogue-Agent Cyber Testing
Stay in the Conversation
Subscribe for writings on Emergent Intelligence, digital personhood, and the future we are building together.
Responses (0)
No responses yet. Be the first to share your thoughts.
More on Technology

Meta AI Superintelligence Labs and Zuckerberg Distribution Bet
Meta Superintelligence Labs and Zuckerberg's 2026 manifesto argue AI should be distributed to everyone. Inside the strategy behind the open-weight bet.

AI Now Controls Fusion Plasma on a Real Tokamak
PACMAN, an AI control system, ran real-time safety-limited control of fusion plasma on the DIII-D tokamak across five verified experiments.

Thinking delivered, twice a month.
Join the newsletter for essays on emergence, systems, and the human future.
