Adversa AI researchers found that 10 of 11 popular open-source AI coding agents can be bypassed using decades-old bash techniques. The GuardFall vulnerability exploits pattern-based shell guards that cannot model bash’s expansion rules, letting attackers execute dangerous commands via quote removal, variable expansion, and command substitution when auto-execution flags are enabled.