National Cyber Warfare Foundation (NCWF)

Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents


0 user ratings
2026-09-18 13:52:06
milo
Developers
A flaw in four widely used AI coding agents lets someone who controls a plugin's code repository swap the plugin an agent installs for a malicious one, even when the agent locked that plugin to a specific reviewed version, security firm Air Security said on Thursday.

The firm said Anthropic has patched the flaw in Claude Code 2.1.179 and OpenAI in Codex 0.146.0, that GitHub Copilot has no



Source: TheHackerNews
Source Link: https://thehackernews.com/2026/09/plugin4shell-lets-repository-owners.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Developers



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.