Tag: shell injection
2 articles

Invisible Screen Text Exposes Android AI Agents to Code Injection Attacks
Researchers found that a simple payload could launch a code injection attack on four open-source Android agent frameworks, successfully executing commands on the host's system in every trial. This alarming vulnerability allows attackers to exploit AI agents by manipulating text on the screen, turning a harmless string into a malicious command.

GuardFall Exposes AI Coding Agents to Shell Injection Risks
Researchers at Adversa AI have uncovered a shocking weakness, dubbed GuardFall, that lets advanced open-source coding agents slip past safety filters and execute destructive shell commands, exposing them to shell injection risks. This gap between text-based checks and shell execution leaves a trail of vulnerability wide open to exploitation.