PhantomFix (CVE-2026-90999) is a critical vulnerability in Sentry Seer's autonomous autofix: a fabricated error report sent to a public DSN can reach the coding agent and lead to code execution and access to connected repositories. It's a concrete instance of a class we described earlier — and the same manipulation works against every leading LLM we tested. Full details and a demo are coming; if you run this setup, you might want to pause it for now.