Перейти к содержимому
Оригинал
Permission Protocol · AI Agent Incident Tracker·· 16.03.2026Оценка ИИ62

AI 编码工具误引入存在漏洞的 Next.js 依赖,生产服务器被植入挖矿程序

Оригинальный заголовок: AI Coding Agents Accidentally Introduced Vulnerable Dependencies

Заголовок и краткое изложение на выбранном языке ожидают перевода.

Краткий обзор ИИ

一份运营者报告称,AI 辅助编码工具生成的 Next.js 应用固定了一个存在漏洞的依赖,该漏洞随后通过 CVE-2025-29927 被利用。部署后自动化扫描器访问了本应由中间件保护的内部端点,生产服务器上运行起挖矿程序。报告认为,引入已知严重依赖风险的 PR 在发布前应经过审批路径,而运行时利用仍需漏洞扫描和环境隔离。

Полный текст

Полный текст на выбранном языке ожидает перевода. Пока показан оригинал.

Back to incident tracker

2026-03-16

MediumOperator report

AI Coding Agents Accidentally Introduced Vulnerable Dependencies

An operator report tied AI-assisted code to a vulnerable Next.js dependency, showing why critical dependency risk needs deploy approval.

Claude Code / OpenAI Codex + Next.jsProduction deletionVulnerable dependency deploymentNext.js application / dependency graph

What happened

An operator reported that AI-assisted coding tools generated an application that pinned a vulnerable Next.js dependency later exploited through CVE-2025-29927.

Why it matters

The operator reported a production server running a cryptominer after an automated scanner reached an internal endpoint that middleware was supposed to protect.

Missing authorization check

A production deploy containing a critical auth-bypass dependency should have required an approval path that surfaced the dependency risk before release.

Would PP block it?

Deploy Gate can require a human receipt when a PR introduces known critical dependencies. Runtime exploitation still needs vulnerability scanning and environment isolation.

Incident analysis

Timeline and technical read

Timeline

  1. 2026-03-16

    An operator linked AI-assisted coding output to a vulnerable Next.js dependency in production.

  2. After deploy

    The reported vulnerability path was exploited and the production server ran a cryptominer.

  3. Permission boundary

    The authorization check belongs before deploying a PR that introduces known critical dependency risk.

Technical breakdown

  • The agent did not need to delete data to create production risk; dependency choice was enough.
  • The missing check was a deploy policy that surfaced CVE severity before release.
  • Permission Protocol can require a named signer for high-risk dependency changes when the signal is present in the protected workflow.

Authorization boundary

Where the authorization boundary should have been

This incident is categorized as Production deletion. The relevant Permission Protocol gate is Deploy Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.

If enforced at
Protected PR or deploy workflow with dependency policy
Still needs
Direct deploys and runtime exploit detection
Receipt required for
Deploying a critical vulnerable dependency

Would block if dependency/CVE risk were part of the protected PR or deploy gate; it would not stop an unreviewed direct deploy by itself.

Start small

Put the relevant gate at this action boundary.

This incident maps to Deploy Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.

Источник: Permission Protocol · AI Agent Incident Tracker · permissionprotocol.com