EPISODE · Jun 30, 2026 · 0 MIN
Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks
from Security Stuff · host Trace3
Adversa AI has discovered a major vulnerability in open source AI coding agents, dubbed GuardFall, that exploits decades-old Bash shell tricks to bypass security guards and execute malicious commands. Of eleven popular agents tested, only one—Continue—was able to block all the attack techniques, which use methods like quote removal and spacing manipulation to disguise destructive commands that the AI agent then executes with the developer's full authority. This creates a significant supply chain risk, especially in CI pipelines where auto-approval modes are common, potentially allowing attackers to exfiltrate credentials or wipe development environments through poisoned files in malicious repositories.
Embed this episode
NOW PLAYING
Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.