{"data":{"id":"abf945cf-f944-4094-9a7e-833ddd560aa9","title":"VTCode is vulnerable to Arbitrary Command Execution via an ANSI-C Quote Bypass of the find Approval Check","summary":"CVE-2026-104247 affects vtcode versions below 0.171.5. An empty ANSI-C quote spliced into a find flag (for example -exe$''c) bypasses the is_destructive_find_option check, so the command is still treated as a safe find. Once the agent has learned that find family from three prior approvals, prompt_tool_permission auto-approves it and the shell runs it as the user running VTCode, with no new prompt. Exploitation requires a local session, those prior approvals, and something that can steer the agent, such as indirect prompt injection.","solution":"Upgrade to VTCode 0.171.5 or later. Until upgrading, do not rely on learned find approvals. The 0.171.5 release (PR #778, commit 5840697cd0dc8f94b9b53d88185329eecba8de11) refuses family learning for path-qualified find, mixed-case or quote-spliced flags, wrapper and environment prefixes, and compound commands.","labels":["security"],"sourceUrl":"https://research.jfrog.com/vulnerabilities/vtcode-is-vulnerable-to-arbitrary-command-execution-via-an-ansi-c-quote-bypass-of-the-find-approval-check-cve-2026-104247-jfsa-2026-001694179/","publishedAt":"2026-10-05T00:00:00.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"medium","attackType":["prompt_injection","other"],"issueType":"vulnerability","affectedPackages":null,"affectedPackageNames":null,"affectedPackageRefs":null,"affectedVendors":[],"affectedVendorsRaw":["VTCode"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":null,"disclosureDate":"2026-10-05T00:00:00.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","confidentiality"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null}}