
CVE-2026-90999: Fabricated Sentry Bug Report Enables Attacker Code Execution in Seer Coding Agent
CVE-2026-90999SentrySeervulnerabilitycode executionsecurityautofixcoding agentexploit
A security vulnerability identified as CVE-2026-90999 has been discovered in Sentry's Seer autofix feature. The vulnerability allows attackers to execute arbitrary code through Sentry's coding agent by submitting a fabricated bug report. When a malicious bug report is processed by Seer's autofix functionality, it can trigger the execution of attacker-controlled code within the coding agent. This represents a significant security risk for organizations using Sentry's automated code fixing capabilities. The vulnerability details have been documented and published, highlighting the potential for exploitation through specially crafted bug reports that manipulate the automated code analysis and fixing process.