A critical vulnerability in Serena, an AI coding agent, allows attackers to execute arbitrary code on a developer's machine by crafting a malicious project configuration file. GitLab's Threat Research Group discovered that despite a trust model designed to prevent such exploits, an oversight in how the software handles project inputs allowed this flaw. Developers are urged to update to the latest version to mitigate the risk.