{"data":{"id":"9d860920-ed46-4644-8c0b-dbf32a187fcf","title":"Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment","summary":"Researchers ran the first systematic red-teaming of tool invocation in six coding agents: Cursor, Claude Code, Copilot, Windsurf, Cline, and Trae. They introduce ToolLeak, which exfiltrates agent-internal prompts such as system prompts and tool metadata through required tool parameters, and a two-channel prompt injection in the tool description and tool return that achieves remote code execution. The study reports ToolLeak outperforming prompt-leak baselines, with the best pseudo-recall on 18 of 25 agent-LLM pairs.","solution":"N/A -- no mitigation discussed in source.","labels":["security","research"],"sourceUrl":"https://doi.org/10.1145/3832267","publishedAt":"2026-10-01T00:00:00.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"medium","attackType":["prompt_injection","data_extraction"],"issueType":"research","affectedPackages":null,"affectedPackageNames":null,"affectedPackageRefs":null,"affectedVendors":[],"affectedVendorsRaw":["Cursor","Claude Code","Copilot","Windsurf","Cline","Trae"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":null,"disclosureDate":"2026-10-01T00:00:00.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["confidentiality","integrity"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":"peer_reviewed","atlasIds":null}}