| Mobile Web

Three trust vulnerabilities found in Claude Code, Gemini CLI and Codex

A shared trust risk has been identified in three AI coding agents - Claude Code, Gemini CLI and Codex - in which malicious GitHub issues can influence subsequent agent runs. Security firm Nobi Security found trust boundaries can break across tool permissions, sandbox isolation and shared workspaces. Researchers said the structure could enable remote code execution, data leaks and persistent control of follow-on agents. Google rated the issue at CVSS 10.0 and adjusted trust mechanisms.