← Back to feed
AI SecurityEmerging1 sourceSep 18, 2026 · 11:01via The Hacker News

Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents

Brief

A flaw in four widely used AI coding agents lets someone who controls a plugin's code repository swap the plugin an agent installs for a malicious one, even when the agent locked that plugin to a specific reviewed version, security firm Air Security said on Thursday.

The firm said Anthropic has patched the flaw in Claude Code 2.

  • 179 and OpenAI in Codex 0.
  • 0, that GitHub Copilot has no
Read more on The Hacker News→