AnalysisDevelopersSeptember 18, 2026

Plugin4Shell flaw lets repo owners swap pinned plugin code in AI coding agents

Air Security found four AI coding agents fetch a plugin's commit-hash snapshot but never verify the code matches it, so a repo owner can point a hash-shaped branch name at malicious code. Anthropic patched Claude Code 2.1.179 and OpenAI patched Codex 0.146.0; GitHub Copilot has no fix and Google won't patch the retiring Gemini CLI.

1 source

More stories today

Open the live feed