Security researchers disclosed critical vulnerabilities across three major AI coding agents that could let low-privileged attackers execute code on CI/CD systems or exfiltrate secrets. Google’s Gemini CLI had a maximum-severity command-injection flaw triggerable via a crafted configuration file, executing code on the build host before any sandbox started. Anthropic’s Claude Code had a separate flaw that let attackers exfiltrate API keys character-by-character via a public download counter used as a covert side channel, and OpenAI’s Codex had a related workflow issue where one agent pass could tamper with instructions read by a later pass. All three vendors have since patched or mitigated the flaws, and no confirmed in-the-wild exploitation had been reported as of disclosure.