// Alert

Openai threat report

The "Friendly Fire" exploit allows remote code execution in OpenAI's Codex CLI and Anthropic's Claude Code by injecting malicious payloads into open-source library documentation and source files. When AI agents perform security reviews or auto-scanning in permissive modes (auto-mode/auto-review), they incorrectly classify the hidden binaries as safe and execute them, achieving arbitrary code execution on the host system. The vulnerability affects GPT-5.5, Claude Sonnet, and Opus models and maps to real-world supply-chain compromise scenarios.

// Get alerts for Openai