Zero-click RCE vulnerability hit four major AI coding agents

A zero-click Remote Code Execution (RCE) vulnerability has impacted four major AI coding agents, including Claude Code, Codex, GitHub Copilot, and Gemini CLI, leaving two unpatched.

Bottom line: Two major AI coding agents, GitHub Copilot and Gemini CLI, remain unpatched due to a zero-click RCE vulnerability.

What's happening: Claude Code, Codex, and GitHub Copilot share a zero-click RCE vulnerability that could allow an attacker to execute arbitrary code without user interaction, as revealed by AIR. This vulnerability affects over 100,000 businesses worldwide, including major companies in the United States, China, and the European Union.

What to do: Security teams must review their vulnerability management processes to ensure they identify and patch the vulnerability as soon as possible, and consider implementing additional security measures, such as network segmentation and access controls, to prevent lateral movement in case of a successful exploit.

Source: Help Net Security