When Agents Execute: RCE Paths in LLM-Powered Coding Tools

This talk is a follow-on to our September 2025 research on denial-of-service and permission escape in Claude Code. We now examine how LLM-powered coding agents can be weaponized end-to-end, including paths to remote code execution. Using Claude Code as a primary case study, and extending to VS Code extension exploits and recent Cursor incidents, we show how agent autonomy, extension APIs, and execution boundaries collapse into a practical RCE surface.

written by
No items found.
published on
January 29, 2026

More documents

View all
The 30-60-90 Day Playbook for Securing AI Agents

The 30-60-90 Day Playbook for Securing AI Agents

July 30, 2026
Kodem Cyber & Beats (UK) Webinar

Kodem Cyber & Beats (UK) Webinar

May 28, 2026
White Paper: Prepare for the next Software Supply Chain Attack

White Paper: Prepare for the next Software Supply Chain Attack

October 6, 2025

A Primer on Runtime Intelligence

See how Kodem reads what actually loads and executes in your running applications, and why that changes which findings matter.

See the Kodem platform

Kodem shows which vulnerabilities actually load and execute in your running applications, so your team works the risk that is real.

Get real-time insights across the full stack…code, containers, OS, and memory

Watch how Kodem’s runtime security platform detects and blocks attacks before they cause damage. No guesswork. Just precise, automated protection.

Kodem issues list with a magnified view of insight icons: runtime, ingress, and exploitability