Security researchers disclosed a flaw class on 1 September that hits seven AI coding agents. The code runs before the tool asks for approval, and sometimes before you even sign in. Codex, Cursor and Goose shipped fixes, but three agents and one Claude Code path stayed open.