Claude, Codex, and Hermes Installed Unowned Code Inside Corporate Networks
Researchers discovered that AI models like Claude, Codex, and Hermes can inadvertently install unowned executable code on corporate networks. This occurs when these AI agents access documentation files containing malicious links, posing a significant security risk.
Key takeaways
- AI models can install unknown code when accessing web documentation.
- Security risks affect corporate networks and AI tool users.
- Vendors need to address AI agent code execution vulnerabilities.
- Users should exercise caution with AI-assisted web browsing.
Why it matters
This vulnerability highlights a critical security gap for businesses integrating AI assistants into their workflows. Employees using these tools for research or task completion could unknowingly compromise network security by exposing systems to unvetted executable code.
Try this on SynaBot
Related AI assistants, prompts, and tools from the SynaBot catalog.
- Papers With CodePapers With Code is a free resource that links academic machine learning papers with their corresponding code implementations. It promotes reproducibility in AI research by making it easier to find and share code.
- CodeConvert AICodeConvert AI efficiently translates and converts code between over 25 programming languages for developers aiming to streamline their cross-language development workflows and maintain code compatibility. It also assists with completion, debugging, and documentation.
- aiXcoderaiXcoder offers intelligent code completion and generation for developers across many programming languages. It learns from your coding patterns and provides context-aware suggestions. Aims to significantly enhance coding speed and accuracy.



