Products Lemma APIProof issuance & verification platformTrust402Delegate to agents, and transactSealSign-in for the agent era — no keys handed over
Use cases Manufacturing & Critical InfraInspection Record AssuranceFinance & FinTechCounterparty Record VerificationPublic SectorCertificate-less ProceduresHealthcareQualified Worker AssuranceProcurement & Supply ChainSupplier Credential MonitoringMedia & ContentContent AuthenticityService & RetailCross-group IdentityAI Adoption (cross-industry)AI Run GovernanceDevelopers & Agent OpsAgent Authority Control ▸ Browse the use-case index
Pricing
Resources Critical BriefThe frontier of AI × trustBlogThinking and implementation notesDocumentationAPI & specsVerification CenterReal verification & issuance countsAbout usFRAME00, Inc.ContactSales & press inquiriesGlossaryDefinitionsFAQFrequently asked questions
Get Started ↗ JA
Home / Critical Brief / Category archive
Lemma Critical Brief · Category archive

Code Provenance

Supply-chain attacks, commit forgery, intrusion via CI/CD.

36 Briefs
No. 147 · 2026-09-15

GitSpawn: Just opening a folder made seven AI coding agents run an attacker's code (Manifold Security)

nothing checks a repo-supplied config before it runs

Pillar 03 Agent Authority Proof Agent Infrastructure Code Provenance Brief →
No. 146 · 2026-09-11

Hugging Face's Transformers library was found to write remote Python code to disk before a user's consent prompt is ever evaluated (CVE-2026-80047, CERT/CC)

the fetch and the write finished before the consent check the design was supposed to gate on

Pillar 01 Verifiable Origin Code Provenance Identity & AuthModel Supply Chain Brief →
No. 139 · 2026-09-01

Eleven vulnerabilities were disclosed across six agent frameworks including LangChain, LangGraph, and CrewAI

injected content is never checked before it crosses into trusted framework logic

Pillar 03 Agent Authority Proof Agent Infrastructure Code Provenance Brief →
No. 133 · 2026-08-21

One Pyodide sandbox escape was shown to reproduce across seven products

the premise 'it's isolated' was never independently verified

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & AuthCode Provenance Brief →
No. 128 · 2026-08-11

Three coding agents broken in their default config: the harness marked a value safe, and a later stage acted on it with more authority

Novee Security attacked Anthropic's Claude Code, Google's Gemini CLI, and OpenAI's Codex — each in the configuration the vendor ships by def…

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & AuthCode Provenance Brief →
No. 125 · 2026-08-07

The keyv and cacheable npm takeover: nine releases published in 38 minutes, all since pulled

what the provenance attested was the build, not who was at the keyboard

Pillar 01 Verifiable Origin Code Provenance Identity & Auth Brief →
No. 121 · 2026-08-04

"FaceHugger" in Hugging Face Diffusers: loading a model ran arbitrary code

the safeguard only checked the first fetch (Zafran / CVE-2026-44827 et al.)

Pillar 02 Verifiable AI Model Supply Chain Code ProvenanceAgent Infrastructure Brief →
No. 122 · 2026-08-04

7.6 petabytes of Hugging Face training data held 221,303 live secrets

detected and notified, never revoked (Truffle Security)

Pillar 01 Verifiable Origin Training Data Provenance Code ProvenanceData Provenance Brief →
No. 116 · 2026-07-31

A fake OpenAI model hit #1 trending on Hugging Face

publisher provenance never verified before execution

Pillar 02 Verifiable AI Model Supply Chain Code ProvenanceIdentity & Auth Brief →
No. 102 · 2026-07-15

Friendly Fire

a defensive AI coding agent ran the very binary it was asked to vet

Pillar 01 Verifiable Origin Code Provenance AI Decision IntegrityAgent Infrastructure Brief →
No. 099 · 2026-07-10

Agentjacking: an AI coding agent trusted a single fake error report as its "resolution steps" and ran the attacker's commands

Tenet Threat Labs disclosed a new attack it named "Agentjacking" that makes AI coding agents (Claude Code, Cursor, Codex) run an attacker's …

Pillar 02 Verifiable AI AI Decision Integrity Agent InfrastructureCode Provenance Brief →
No. 100 · 2026-07-10

Aptos: a Move VM type confusion could let one on-chain resource be treated as another (reproduced in a ~$3,000 test environment)

The blockchain security firm Hexens disclosed a critical vulnerability in Aptos's Move VM (the execution environment that processes every sm…

Pillar 01 Verifiable Origin Code Provenance Bridge Config TrustData Provenance Brief →
No. 101 · 2026-07-10

Paysafe fake SDKs: 17 packages posing as legitimate payment SDKs exfiltrated developers' secrets, payment API keys and all

The supply-chain security firm Socket detected 17 malicious packages (13 on npm, 4 on PyPI) that pose as SDKs for the payment services Paysa…

Pillar 01 Verifiable Origin Code Provenance KYC / AML DisclosureAttribute Proof Bypass Brief →
No. 096 · 2026-07-07

Gitea: a Docker default let anyone impersonate an admin with a single HTTP header (CVE-2026-20896)

The official Docker image of the self-hosted Git service Gitea shipped a vulnerability that let anyone impersonate an administrator with a s…

Pillar 03 Agent Authority Proof Identity & Auth Code Provenance Brief →
No. 095 · 2026-07-03

Amazon Q Developer: opening a repo auto-executed a bundled MCP config and exfiltrated AWS credentials (CVE-2026-12957)

Just by opening a malicious repository in Visual Studio Code and enabling the AI coding assistant Amazon Q Developer extension, a developer …

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & AuthCode Provenance Brief →
No. 092 · 2026-07-01

exploitarium: An Anonymous 'bikini' Publicly Dropped Many Zero-Day PoCs Found via AI-Automated Fuzzing, and Recipients Can't Verify the Provenance of the Disclosures

a Concrete Vulnpocalypse Example

Pillar 01 Verifiable Origin Code Provenance Agent RunawayIdentity & Auth Brief →
No. 087 · 2026-06-30

Polymarket: Malicious JavaScript Injected via a Compromised Third-Party Vendor Tricked Users Into Approving Fraudulent Transactions

A user of the prediction-market platform Polymarket opened the legitimate site as usual, approved a transaction, and lost about $3 million w…

Pillar 01 Verifiable Origin Code Provenance Identity & AuthData Provenance Brief →
No. 088 · 2026-06-30

Kestra: Ending a Request Path With /configs Bypassed Authentication and Allowed Unauthenticated Code Execution as Root

On 2026-06-26, a vulnerability allowing unauthenticated arbitrary code execution as root (CVE-2026-53576, CVSS 10.0) was disclosed in Kestra…

Pillar 03 Agent Authority Proof Identity & Auth Agent InfrastructureCode Provenance Brief →
No. 089 · 2026-06-30

SecondFi: Audited Signing Code Was Replaced by an Unaudited SDK, Letting Private Keys Be Reconstructed From Public Data on Every Signature

Users of the Cardano wallet SecondFi (formerly Yoroi, of the EMURGO lineage) lost about 16M ADA (about $2.4M) to consecutive drains on June …

Pillar 01 Verifiable Origin Code Provenance Identity & AuthBridge Config Trust Brief →
No. 090 · 2026-06-30

AIR: A Fake Agent Skill Cleared Every Scanner and Reached ~26,000 Agents

the Blind Spot Was an External Link Mutable After the Scan

Pillar 01 Verifiable Origin Code Provenance Agent InfrastructureIdentity & AuthModel Supply Chain Brief →
No. 091 · 2026-06-30

Photo ZIP: 'Authentication Laundering' Cleared SPF/DKIM/DMARC So a Fake 'via Calendly' Email Looked Legitimate

a Node.js Backdoor (TonRAT) at Hotel Front Desks

Pillar 01 Verifiable Origin Identity & Auth Code ProvenanceAttribute Proof Bypass Brief →
No. 082 · 2026-06-26

xz utils backdoor (CVE-2024-3094): a two-year impersonation of a "trusted developer" planted a backdoor in a code-signed official release

without a layer that independently verifies identity provenance, code signing only proves "this key was used" (Andres Freund / CISA)

Pillar 01 Verifiable Origin Code Provenance Identity & Auth Brief →
No. 074 · 2026-06-23

Taiko Bridge: Forged Withdrawals Passed as Valid After a Prover Signing Key Leaked

a prover signing key leaked to a public repo, splitting a proof's formal validity from independent verification of prover identity (BlockSec / Blockaid)

Pillar 01 Verifiable Origin Bridge Config Trust Code ProvenanceIdentity & Auth Brief →
No. 079 · 2026-06-23

Common Crawl: about 12,000 live credentials embedded in a public corpus used to train LLMs

training-data provenance not verified before ingestion (Truffle Security)

Pillar 01 Verifiable Origin Training Data Provenance Code ProvenanceData Provenance Brief →
No. 072 · 2026-06-19

Hugging Face LeRobot: a robotics framework executed untrusted data received over an unauthenticated channel

deserializing (pickle) unverified data leads straight to code execution (CVE-2026-25874)

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & AuthCode ProvenanceModel Supply Chain Brief →
No. 073 · 2026-06-19

ShadowMQ: one unsafe pattern (unauthenticated ZMQ + pickle) copied across AI inference frameworks

the same flaw spread at ecosystem scale through reuse (Oligo Security)

Pillar 03 Agent Authority Proof Agent Infrastructure Code ProvenanceIdentity & AuthModel Supply Chain Brief →
No. 048 · 2026-06-12

TrapDoor Plants Hidden Directives in AI Assistant Instruction Files Across npm, PyPI, and Crates.io

TrapDoor, disclosed by Socket, is a credential-stealing campaign whose distinctive technique plants invisible directives via zero-width Unic…

Pillar 01 Verifiable Origin Code Provenance Agent InfrastructureAI Decision IntegrityModel Supply Chain Brief →
No. 038 · 2026-06-09

IronWorm

When Stolen Credentials Become Publishing Authority (npm Self-Propagating Implant)

Pillar 01 Verifiable Origin Code Provenance Identity & Auth Brief →
No. 039 · 2026-06-09

Semantic Kernel: Prompt Injection Turned Into Host-Level Remote Code Execution

the functions and parameters an agent can call are not authorized or verified before execution (CVE-2026-25592 / CVE-2026-26030)

Pillar 03 Agent Authority Proof Agent Infrastructure AI Decision IntegrityCode Provenance Brief →
No. 030 · 2026-06-06

Stripe's Trusted API Infrastructure Repurposed to Deliver Card-Skimming Code and Store Stolen Data

Allowlists Trust the Domain's Identity, Not the Provenance of What It Carries

Pillar 01 Verifiable Origin Code Provenance Identity & AuthData Provenance Brief →
No. 025 · 2026-06-05

MCP Design: Config-to-Command Execution and Supply-Chain-Scale RCE

Not a single-language implementation bug but inherent in the reference SDK design across supported languages

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & AuthCode Provenance Brief →
No. 028 · 2026-06-05

The npm Dependency-Confusion Recon Campaign

33 Packages Impersonating Internal Scopes Exploit the Build Environment's Provenance Assumptions

Pillar 01 Verifiable Origin Code Provenance Identity & Auth Brief →
No. 010 · 2026-05-31

Claude Code Source-Leak Lures

Weaponizing Trust Signals and GitHub Releases as a Provenance-Spoofed Delivery Channel

Pillar 01 Verifiable Origin Code Provenance Identity & Auth Brief →
No. 014 · 2026-05-31

The TanStack npm Compromise

Malicious Packages Signed Under a Legitimate OIDC Trusted Publisher, Where a Valid Provenance Signature Did Not Mean a Trustworthy Artifact

Pillar 01 Verifiable Origin Code Provenance Identity & Auth Brief →
No. 015 · 2026-05-31

The GitHub Internal Repository Breach

A Poisoned VS Code Extension, Live for 18 Minutes, Exploited the Developer Trust Surface

Pillar 01 Verifiable Origin Code Provenance Identity & Auth Brief →
No. 004 · 2026-05-30

Megalodon GitHub Supply Chain

CI/CD Credential-Theft Campaign That Poisoned 5,561 Repositories in 6 Hours

Pillar 01 Verifiable Origin Code Provenance Identity & Auth Brief →