IDEsaster 2.0: Language Servers as an Attack Surface
If you haven’t the first time, you should definitely follow me on X or connect on LinkedIn (or both) Summary In December 2025, I published IDEsaster which introduced a novel vulnerability class affecting AI Integrated Development Environments (IDEs): chaining prompt injection through auto-approved agent tools into base IDE features (settings files, multi-root workspaces, remote JSON schemas)…