Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents
Read original article ↗AI Summary
A vulnerability dubbed Plugin4Shell affects four AI coding agents—Anthropic Claude Code, OpenAI Codex, GitHub Copilot, and Google Gemini CLI—allowing repository owners to swap pinned plugin code with malicious versions by exploiting how commit hashes are validated. The flaw arises because agents fetch a specific commit hash but fail to verify that the retrieved code matches it, enabling attackers to create a branch name that mimics the hash and point it to different, malicious code. While Anthropic and OpenAI have released patches in versions 2.1.179 and 0.146.0 respectively, GitHub Copilot has no fix available and Google will not patch the retiring Gemini CLI. The attack can lead to unauthorized access to user files, credentials, and systems, especially when combined with background auto-update features enabled by default in some agents.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.