#5
The Hacker News
general
September 18, 2026 at 11:01 UTC
Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents
By [email protected] (The Hacker News)
AI Summary
Security firm Air Security disclosed 'Plugin4Shell,' a flaw affecting four widely used AI coding agents — patched in Anthropic's Claude Code 2.1.179 and OpenAI's Codex 0.146.0 — that allows a malicious plugin repository owner to substitute pinned, reviewed plugin code with arbitrary malicious code at install time. GitHub Copilot remains unpatched, and the flaw undermines version-pinning as a supply chain security control in AI-assisted development workflows.
Relevance score: 81.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →