Three AI Coding Agents, Three Ways to Break Them, and One Thing Detection Will Never Give You
I've spent the last week reading through the technical writeups from Novee Security's Black Hat USA 2026 briefing, "Trusted Enough to Run: Breaking AI Agents in Official Workflows." The title sounds broad. The content is not. They found three distinct, exploitable vulnerabilities in three of the most widely used AI coding agents — each in the agent's own repository, each triggered by code the agent itself was asked to review.
The details matter, because they reveal a pattern that detection alone cannot solve.
Claude Code: The Single-Quote Strip
CVE-2026-54316. CVSS v4 score 6.0. Affects Claude Code versions >=0.2.54 and <2.1.163.






