Home / Sep 19, 2026 / Story
0
#5 The Hacker News general September 18, 2026 at 11:01 UTC

Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents

By [email protected] (The Hacker News)

AI Summary

Security firm Air Security disclosed 'Plugin4Shell,' a flaw affecting four widely used AI coding agents — patched in Anthropic's Claude Code 2.1.179 and OpenAI's Codex 0.146.0 — that allows a malicious plugin repository owner to substitute pinned, reviewed plugin code with arbitrary malicious code at install time. GitHub Copilot remains unpatched, and the flaw undermines version-pinning as a supply chain security control in AI-assisted development workflows.

Relevance score: 81.0/100

# More from September 19