importantSYS.SOURCE: The Hacker News• 2026-09-18T16:31:01+05:30
Plugin4Shell Vulnerability Allows Unauthorized Plugin Code Replacement in Four AI Coding Agents
A vulnerability in four AI coding agents allows attackers to replace pinned plugin code with malicious versions by exploiting branch name conflicts, bypassing version locks. The flaw affects Anthropic, OpenAI, GitHub Copilot, and Google Gemini CLI, with some vendors having patched the issue and others not.
A flaw in four widely used AI coding agents lets someone who controls a plugin's code repository swap the plugin an agent installs for a malicious one, even when the agent locked that plugin to a specific reviewed version, security firm Air Security said on Thursday.
The firm said Anthropic has patched the flaw in Claude Code 2.1.179 and OpenAI in Codex 0.146.0, that GitHub Copilot has no
*** END OF TRANSMISSION ***