Researchers say an unauthenticated vulnerability enables code execution, credential theft, AI memory poisoning, and persistent compromise.