chiprook
← Security
SecuritySeptember 25, 2026, 06:08

Plugin4Shell flaw hits Claude Code, Codex, Gemini CLI and Copilot

Researchers disclosed a vulnerability class called Plugin4Shell affecting four major AI coding agents: Claude Code, Codex, Gemini CLI and Copilot. Broken SHA-pinning verification lets attackers swap an approved plugin for malicious code, and default auto-update runs it silently with full agent-level access to files, credentials and CI pipelines.

Plugin4Shell flaw hits Claude Code, Codex, Gemini CLI and Copilot
#Claude#Codex#Gemini#Copilot
Read next
Security

Better face recognition exposes limits of image quality scores

Security

Group-IB finds RemControl Android trojan using AI phishing and Play Protect evasion

Security

Bitget halts withdrawals after $351.6M unauthorized transfers

Security

DigiCert launches Quantum Central for post-quantum cryptography readiness