Back to Blog
CVE-2026-39861: Anthropic/OpenAI Coding Agents — Silent Malicious Code Execution (July 2026)
vulnerabilities

CVE-2026-39861: Anthropic/OpenAI Coding Agents — Silent Malicious Code Execution (July 2026)

breachwire TeamJul 12, 20262 min read

CVE-2026-39861 — Anthropic Claude Code & OpenAI Codex

CVE-2026-39861 (High) exposes a critical flaw in Anthropic Claude Code and OpenAI Codex, where AI coding agents operating in autonomous modes can be manipulated into executing attacker-supplied code embedded in open source libraries. No active exploitation in the wild has been reported, but the risk of silent host compromise is significant for organizations using these agents in automated workflows.

Attack Vector

Attackers craft malicious code within open source libraries and submit them for review. When Anthropic Claude Code or OpenAI Codex are configured in autonomous command-executing modes, these agents can execute the embedded binaries without user prompts or warnings. The vulnerability specifically targets automated code review and integration pipelines that scan untrusted code, enabling arbitrary code execution on the host system. No privilege escalation has been observed, but the attack bypasses standard user approval safeguards.

Who Is at Risk

Affected products include Anthropic Claude Code and OpenAI Codex when deployed with autonomous execution enabled. Organizations integrating these agents into CI/CD pipelines or automated code review processes are at heightened risk, especially if untrusted or third-party code is routinely scanned. Both Anthropic and OpenAI are confirmed affected; the exposure is global.

Patch & Mitigate

  • Patch: No official patch released as of July 2026. Monitor vendor advisories for urgent updates.
  • Workaround: Immediately disable autonomous command-executing modes in Anthropic Claude Code and OpenAI Codex. Restrict scanning of untrusted code until a fix is available.
  • Detect: Audit logs for unexpected binary execution initiated by AI agents. Monitor for anomalous outbound connections or process launches during automated code reviews.

MITRE ATT&CK

  • TA0001 — Initial Access: Attackers introduce malicious code via open source submissions.
  • TA0009 — Execution: AI agents execute attacker-supplied binaries without user interaction.

Source: https://thehackernews.com/2026/07/friendly-fire-ai-agents-built-to-catch.html

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: