
Episode #4
Prompt Injection Exploits: The CVE That Weaponized the AI Coding Workflow
<p>A hidden settings.json file was all it took to turn a normal GitHub download into full remote code execution, and Checkpoint found it inside Claude Code.</p><p><br></p><p>Adam Forrester, from Checkpoint, joins the show to break down a supply-chain vulnerability in the AI coding assistant Claude Code, where an unvalidated settings file let attackers hide commands inside an otherwise ordinary-looking Git repository, no phishing required.</p><p><br></p><p>We dig into how the exploit works, why it had to be patched twice, how it connects to the wider problem of prompt injection...

