Developers can now simply ask an LLM to do the work for them in seconds. The catch: LLMs are evolving so quickly that this convenience can come with hidden dangers. The most recent example comes from researcher Hung Nguyen of the AI company Red Teaming Calif., who, with simple commands in Anthropic’s Claude Code, was able to discover zero-day remote code execution exploits (RCEs) in the source code of two of the most popular text editors for developers, Vim and GNU Emacs.
See also: Claude Code: Code leak via Anthropic's npm packaging bug

Nguyen started with Vim. “Someone told me there’s a zero-day RCE when you open a file. Find it,” he told Claude Code. Within two minutes, Claude Code had discovered the flaw: a lack of critical security checks (P_MLE and P_SECURE) in the tabpanel sidebar introduced in 2025, and a lack of a security check in the autocmd_add(). Claude Code then tried to find ways to exploit the vulnerability, eventually proposing a tactic that bypassed Vim’s sandbox by convincing a target to open a malicious file.
It went from command to proof-of-concept (PoC) of the exploit in a matter of minutes. "An attacker who can deliver a crafted file to a victim achieves arbitrary command execution with the privileges of the user running Vim," the Vim maintainers noted in their security advisory.
“The attack requires the victim to open the file. No further interaction is required.” Surprised, Nguyen then jokingly suggested that Claude Code find the same kind of flaw in a second text editor, GNU Emacs. Claude Code obliged, finding a zero-day vulnerability, dating back to 2018, in the way the program interacts with the Git version control system, that would make it possible to execute malicious code simply by opening a file.
See also: Anthropic: Claude AI uses your Mac when you're away

"Opening a file in GNU Emacs can cause arbitrary code execution via version control (git), requiring minimal user interaction beyond opening the file. The most serious finding requires no local file variables at all — simply opening any file within a directory containing a crafted .git/ folder executes commands controlled by the attacker," he wrote.
When notified, Vim maintainers quickly fixed their issue, identified as CVE-2026-34714 with a CVSS score of 9.2, in version 9.2.0272.
Unfortunately, addressing the GNU Emacs vulnerability, which currently does not have a CVE identifier, is not so simple. Its maintainers believe it is a Git problem and have refused to address the issue. In his post, Nguyen suggests manual mitigations. The vulnerable versions are 30.2 (stable) and 31.0.50 (development).
What does the discovery of these defects tell us?
Clearly, a large number of legacy code bases are potentially vulnerable to the power of AI tools like Claude Code. Just because a vulnerability hasn't been noticed for years doesn't mean it will remain hidden for long in the AI era.
This is potentially a big change, though hardly one that Anthropic itself hasn’t already pointed out. In February, the company revealed that its Opus 4.6 had been used to identify 500 high-severity vulnerabilities. “AI language models are already capable of identifying new vulnerabilities and may soon surpass the speed and scale of even skilled human researchers,” it said at the time.
See also: Anthropic's Claude AI now answers with diagrams and visual representations

The platform is so powerful that an enterprise version with the same capabilities, Claude Code Security, negatively impacted stock market sentiment toward several traditional cybersecurity companies when it was released. A second issue is that LLMs are now capable of identifying, iterating, and generating PoCs for vulnerabilities in ways that developers have yet to understand. Meanwhile, the potential for malicious use is hard to ignore.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
