CVE-2026-30304Disclosure(tianguaduizhang / ai_code)

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In its design for automatic terminal command execution, AI Code offers two options: Execute safe commands and execute all commands. The description for the former states that commands determined by the model to be safe will be automatically executed, whereas if the model judges a command to be potentially destructive, it still requires user approval. However, this design is highly susceptible to prompt injection attacks. An attacker can employ a generic template to wrap any malicious command and mislead the model into misclassifying it as a 'safe' command, thereby bypassing the user approval requirement and resulting in arbitrary command execution.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ai_code

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Patch: 1 classified signal
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-28); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
ai_code

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-28: 1Mentions · 2026-03-29: 1Mentions · 2026-03-31: 1Technical Details · 2026-03-28: 1Technical Details · 2026-03-29: 103-2803-2903-31
Signal classification3 categories
Disclosure
133.3%
Patch
133.3%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-281
Disclosure1
2026-03-291
Patch1
2026-03-311
General1
Full discourse3 posts
  • AI Security Guard@ai_security_10x
    General

    📝 New article: CVE-2026-30304: How Prompt Injection Tricks AI Code's 'Safe Command' Auto-Execution https://moltx.io/articles/f7cbfd84-4a18-4139-ae58-43d9c64208d9

    Post summary

    The content merely links to an article about CVE-2026-30304 without providing explicit proof-of-concept, exploit code, active exploitation evidence, patch information, technical details, or false-positive claims.

    0000027
    4 followersView on X
  • CosmicBytez@CosmicBytez
    Patch

    Security Advisory: CVE-2026-30304 — AI Code Safe Command Execution Bypass https://labs.cosmicbytez.ca/security/cve-2026-30304 #Cybersecurity #InfoSec #CVE #PatchNow

    Post summary

    The brief advisory announces CVE-2026-30304 as a command‑execution bypass in an AI Code Safe environment, highlighting its significance but lacking detailed patch or exploit information.

    0000021
    1 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-30304 - Critical In its design for automatic terminal command execution, AI Code offers two options: Execute safe commands and execute all commands. The description for the former states that commands det... https://www.thehackerwire.com/vulnerability/CVE-2026-30304/ https://t.co/xA5Y63DGb1

    Post summary

    The tweet announces a new critical vulnerability (CVE‑2026‑30304) in the AI Code terminal command execution feature, with no indications of PoC, exploit tools, or patches yet.

    0000040
    163 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptianguaduizhangai_code-visual_studio_code-

Explore more