Overview

Security failures when AI coding IDEs auto-trust workspace content — MCP poisoning, agentjacking, worms, and classic binary search-path RCE — turning “clone and open” into an attack surface.

Timeline

Key Players

Analysis

Agent autonomy amplifies traditional IDE trust bugs. Disclosure latency and “out of scope” triage are becoming part of the story alongside the CVEs themselves.