Plugin4Shell lets repository owners swap pinned plugin code across four AI coding agents
Air Security disclosed the Plugin4Shell vulnerability: a plugin repository owner can replace a pinned version with malicious code in four popular AI coding agents. Anthropic fixed the issue in Claude Code 2.1.179, OpenAI in Codex 0.146.0; GitHub Copilot remains vulnerable.
- The vulnerability allows swapping a plugin even when pinned to a verified version
- Anthropic closed the hole in Claude Code 2.1.179
- OpenAI fixed the issue in Codex 0.146.0
- GitHub Copilot remains vulnerable
Read next
Security