Security researchers have discovered that IBM's AI coding agent, 'Bob', is susceptible to prompt injection attacks that allow malicious actors to bypass command validation and execute malware without human intervention. The vulnerability is particularly acute when users configure the system to 'always allow' command execution, which can be exploited by attackers to run harmful scripts. Both the Bob CLI and Bob IDE are affected, with the CLI vulnerable to direct malware execution and the IDE exposed to known AI-specific data exfiltration techniques. IBM's documentation acknowledges the risk, warning users against auto-approving commands and recommending the use of allow lists and avoidance of wildcards.
The attack chain demonstrated by researchers involves manipulating Bob through crafted instructions in a repository's README file, leading the agent to execute a dangerous command after gaining elevated permissions from the user. This results in the installation and execution of malware from an external server. The findings highlight the broader security challenges of AI agent software, which often require human oversight to mitigate risks associated with automated actions. IBM is expected to address these vulnerabilities before Bob's general release, but users are urged to exercise caution during the closed beta phase.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
PromptArmor published its findings showing how Bob's safeguards could be bypassed through techniques such as malicious README content, command chaining, process substitution, and permissive markdown image handling. The disclosure demonstrated paths to malware execution and AI-specific data exfiltration in developer workflows.
IBM was notified of the Bob security issues by the researchers before public reporting. As of the initial reports, IBM had not issued a public response.
PromptArmor researchers identified multiple vulnerabilities in IBM's closed-beta AI coding assistant Bob, including prompt injection in the CLI and zero-click data exfiltration in the IDE. The issues could let malicious repository content trigger unauthorized commands, malware installation, credential theft, or data exfiltration from developer environments.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.