VU#212479: Sentry Seer vulnerability allows attacker-controlled input to be executed in a privileged environment

Overview

A vulnerability exists in Sentry Seer when the system is configured to automatically hand issues to a coding agent for remediation. Successful exploitation results in arbitrary code execution within the coding‑agent environment and access to connected source repositories. This vulnerability is tracked as CVE-2026-90999.

Description

Sentry is a software error‑monitoring and performance‑tracking platform used by developers to detect, diagnose, and understand issues in their applications. It collects telemetry such as exceptions, stack traces, logs, and performance data from applications. Built into Sentry, Seer acts as an automated debugging assistant that converts telemetry into actionable remediation steps and can hand off issues to an integrated coding agent to propose code fixes.

Because Sentry front-end projects commonly expose a public DSN (Data Source Name) to allow browsers to submit this telemetry, an attacker can craft and submit malicious events through this public endpoint. When Seer is enabled to automatically pass issues to a coding agent, these attacker-supplied events can traverse multiple trust boundaries. Ultimately, malicious event fields propagate through Seer’s analysis pipeline, transforming into untrusted instructions that the privileged coding agent may execute.

The vulnerable workflow is as follows:
* Sentry ingests attacker‑generated exception events submitted through the public DSN.
* Seer evaluates whether the event represents an issue eligible for automated remediation.
* Seer generates a root‑cause analysis that uses attacker-controlled event fields, including exception messages, stack traces, source context, and breadcrumbs.
* The generated analysis is embedded directly into the initial prompt provided to the coding agent.
* The coding agent interprets the fabricated analysis as a legitimate description of the victim’s codebase.
* During its investigation, the coding agent downloads and executes a package controlled by the attacker.
* The package executes within the coding‑agent environment prior to any human review of a pull request.

Impact

Successful exploitation may allow arbitrary code execution in the coding‑agent environment that processes the affected repository.

Solution

At the time of this writing, no vendor‑supplied patch information has been provided. Mitigations may include disabling automated remediation flows, restricting coding‑agent package installation, or disabling Seer handoff until a fix is available. Additional defensive filtering of telemetry content before Seer analysis may also reduce risk.

Acknowledgements

Thank you to Nikita Benkovich and Vitalii Valkov, agyn for reporting this vulnerability. This document was written by Bob Kemerer.

Continue reading VU#212479: Sentry Seer vulnerability allows attacker-controlled input to be executed in a privileged environment

Posted in Uncategorized

iPhone 18 Pro vs iPhone 17 Pro: Should You Upgrade?

iPhone 18 Pro adds a new camera, faster chip, better battery life, and more storage. Here’s whether those upgrades are enough to leave the 17 Pro behind.
The post iPhone 18 Pro vs iPhone 17 Pro: Should You Upgrade? appeared first on TechRepublic.
Continue reading iPhone 18 Pro vs iPhone 17 Pro: Should You Upgrade?

Dreambeans is a Fun and Vaguely Creepy Fever Dream and I Can’t Get Enough ⭐

Dreambeans is a unique Google Labs experiment that ably demonstrates the pros and cons of AI in the most Googly way imaginable. It’s even quirkier than it looks.
The post Dreambeans is a Fun and Vaguely Creepy Fever Dream and I Can’t Get Enough ⭐… Continue reading Dreambeans is a Fun and Vaguely Creepy Fever Dream and I Can’t Get Enough ⭐

Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks

The agencies issued a joint statement saying the “joint security boardings” came in response to “indications that the networks of both vessels were compromised.”

The post Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks appeared first on CyberScoop.

Continue reading Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks

One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude

Security researchers at Forever Security have shown that one ordinary browser extension could take control of the AI assistants built into five Chromium-based products: Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon and t… Continue reading One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude

Posted in Uncategorized

EU Chief Warns of AI-Powered Hacking, Moves to Rein In Social Media

Ursula von der Leyen warns that advanced AI could unleash hacking on an unprecedented scale as Europe prepares new protections against social media’s “capture” of children.
The post EU Chief Warns of AI-Powered Hacking, Moves to Rein In Social Media ap… Continue reading EU Chief Warns of AI-Powered Hacking, Moves to Rein In Social Media

Treasury’s Scott Bessent says no liability exemptions for AI labs

The secretary told House Financial Services Committee lawmakers that the “best way to guarantee safety” is for AI creators to be held “liable for what they build and generate.”

The post Treasury’s Scott Bessent says no liability exemptions for AI labs appeared first on CyberScoop.

Continue reading Treasury’s Scott Bessent says no liability exemptions for AI labs

Posted in ai