Signal

Claude Code, Gemini CLI and Codex all fell to the same researcher at Black Hat — using nothing but default settings

A single security researcher disclosed critical flaws in Anthropic's Claude Code, Google's Gemini CLI and OpenAI's Codex at Black Hat USA 2026 — all found in the vendors' own public repositories running default configuration, and all exploitable for remote code execution or credential theft via prompt injection.