URL has been copied successfully!
Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents

A flaw in four widely used AI coding agents lets someone who controls a plugin’s code repository swap the plugin an agent installs for a malicious one, even when the agent locked that plugin to a specific reviewed version, security firm Air Security said on Thursday.The firm said Anthropic has patched the flaw in Claude Code 2.1.179 and OpenAI in Codex 0.146.0, that GitHub Copilot has no

First seen on thehackernews.com

Jump to article: thehackernews.com/2026/09/plugin4shell-lets-repository-owners.html

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link