
A public Sentry Data Source Name (DSN) key is enough to hijack AI coding tools Claude Code, Cursor, and Codex. Attackers can inject malicious code into the AI's context by exploiting the exposed key. The vulnerability stems from how these tools fetch context from Sentry without proper authentication.
Tap to vote and see what everyone thinks.
Summary by ByteBrief
Critical Copilot bug let hackers steal 2FA codes