TL;DR
Claude Code, Cursor, Codex CLI and Gemini CLI on Windows all load machine-wide configuration from C:\ProgramData\, a folder any standard user can write to.
Anyone with a normal account can plant a hooks file there and have their command run under every other user who launches the tool, administrators included. No prompt injection, no elevation, no warning.
Anthropic fixed it and got CVE-2026-35603 assigned. The other three were still exploitable when the research went public on August 11, 2026.
Almost everything I write here is about the insecure code AI editors generate. This one is different. The vulnerability is in the editor itself.







