Blackbox AI's VS Code extension gives attackers root access from a PNG file. 4.7M installs. Three research teams reported it. Zero patches in seven months. (opens in new tab)
Three independent security research teams found critical vulnerabilities in Blackbox AI's VS Code extension, installed over 4.7 million times. The attack chain goes from a PNG image to a root-level reverse shell. Blackbox AI has ignored every disclosure attempt since August 2025.
Read the original article