Security researchers have published a flaw that affected four well-known AI assistants for software development. The tools obtain extensions from online catalogues and request a specific, verified version. However, none of the programs checked whether the delivered file actually matched that version. Anyone controlling a provider's source repository could therefore inject malicious code that ran without any action by the user. Two vendors have fixed the issue, while a solution is still missing for the others.

For mid-sized businesses, the pattern matters more than the individual case. Program code is increasingly written outside the IT department, for example for reports or small interfaces to the ERP.

We recommend recording the assistants in use together with their version, allowing extensions only from approved sources, and giving these tools no access to production systems.