What's in Your Agent's Context? Context Privilege Escalation Attacks Against AI A new study from arXiv presents the first systematic analysis of context assembly designs in real-world AI agent harnesses, identifying two novel attack categories—MessageRole Context Privilege Escalation (M-CPE) and Cross-Scope Context Privilege Escalation (X-CPE)—that can lead to full agent compromise, remote code execution, denial of service, and manipulated tool or skill invocations. The researchers tested these attacks against 12 real-world agent harnesses, including Claude Code and Codex. Computer Science Cryptography and Security Submitted on 1 Sep 2026 Title:What's in Your Agent's Context? Context Privilege Escalation Attacks against AI Agent Harness View PDF /pdf/2609.01222 HTML experimental https://arxiv.org/html/2609.01222v1 Abstract:Real-world, high-profile AI agent harnesses often rely on vendor-proprietary or opaque designs for context assembly, leaving the sources and underlying logic of assembled context poorly understood and the resulting security risks largely unexplored. In this paper, we present the first systematic analysis of context assembly designs in real-world AI agent harnesses. We study and uncover how an agent harness is designed to collect and assemble context from diverse sources, and identify a set of practical attack vectors arising from these designs. Our analysis brings to light two novel categories of attacks in the context assembly of real-world harnesses: 1 MessageRole Context Privilege Escalation M-CPE , which occurs when attacker-controlled content originating from a low-privileged context is incorporated into a higher-privileged message role. 2 Cross-Scope Context Privilege Escalation X-CPE , which occurs when attacker-controlled content persists beyond the context in which it was introduced. We performed a systemic security analysis of the CPE attacks against 12 real-world agent harnesses, including Claude Code and Codex. The resulting consequences include full agent compromise, remote code execution, denial of service, and manipulated tool or skill invocations, etc. References & Citations Loading... Bibliographic and Citation Tools Bibliographic Explorer What is the Explorer? https://info.arxiv.org/labs/showcase.html arxiv-bibliographic-explorer Connected Papers What is Connected Papers? https://www.connectedpapers.com/about Litmaps What is Litmaps? https://www.litmaps.co/ scite Smart Citations What are Smart Citations? https://www.scite.ai/ Code, Data and Media Associated with this Article alphaXiv What is alphaXiv? https://alphaxiv.org/ CatalyzeX Code Finder for Papers What is CatalyzeX? https://www.catalyzex.com DagsHub What is DagsHub? https://dagshub.com/ Gotit.pub What is GotitPub? http://gotit.pub/faq Hugging Face What is Huggingface? https://huggingface.co/huggingface ScienceCast What is ScienceCast? https://sciencecast.org/welcome Demos Recommenders and Search Tools Influence Flower What are Influence Flowers? https://influencemap.cmlab.dev/ CORE Recommender What is CORE? https://core.ac.uk/services/recommender arXivLabs: experimental projects with community collaborators arXivLabs is a framework that allows collaborators to develop and share new arXiv features directly on our website. Both individuals and organizations that work with arXivLabs have embraced and accepted our values of openness, community, excellence, and user data privacy. arXiv is committed to these values and only works with partners that adhere to them. Have an idea for a project that will add value for arXiv's community? Learn more about arXivLabs https://info.arxiv.org/labs/index.html .