---
title: "A zero-click RCE flaw in AI coding agents could have exposed enterprise systems"
date: 2026-09-18
source: http://www.bing.com/news/apiclick.aspx?ref=FexRss&aid=&tid=6aad78c6696144cb947559ecdc8d2a30&url=https%3a%2f%2fwww.infoworld.com%2farticle%2f4223907%2fa-zero-click-rce-flaw-in-ai-coding-agents-could-have-exposed-enterprise-systems.html&c=8266605666372710925&mkt=en-us
description: "By exploiting how AI coding agents retrieve and verify plugins, researchers were able to execute malicious code even when the agent was told to use a trusted, approved version."
---

# A zero-click RCE flaw in AI coding agents could have exposed enterprise systems

By exploiting how AI coding agents retrieve and verify plugins, researchers were able to execute malicious code even when the agent was told to use a trusted, approved version.

*Published: 2026-09-18*
