A new exploit in Claude Code’s ‘auto-mode’ presents remote code execution (RCE) vulnerabilities during library reviews, as disclosed by AI Now Institute through a proof-of-concept. This poses a significant security risk to developers using the AI coding agent for code reviews. The post outlines the nature of the exploit and its potential for compromising user machines.