chiprook
← Security
SecuritySeptember 18, 2026, 18:01

Plugin4Shell lets repository owners swap pinned plugin code across four AI coding agents

Air Security disclosed the Plugin4Shell vulnerability: a plugin repository owner can replace a pinned version with malicious code in four popular AI coding agents. Anthropic fixed the issue in Claude Code 2.1.179, OpenAI in Codex 0.146.0; GitHub Copilot remains vulnerable.

Plugin4Shell lets repository owners swap pinned plugin code across four AI coding agents
#Anthropic#OpenAI#GitHub#Claude
Read next
Security

Kaspersky finds MovieReaper trojan in pirated films, C2 hidden on Solana blockchain

Security

npm Trusted Publishing Abused to Ship GHAPPIER Loader

Security

Orchid Security Delivers AI Readiness Controls With Application-Level Kill Switches

Security

Mandiant: hijacked AI coding session spread Shai-Hulud worm across ~100 repos