Should we expect to see this exploits in the wild soon?
🚨 ZERO-CLICK RCE: “Plugin4Shell” bypasses Git SHA pinning across major AI coding agents. The flaw can silently replace a trusted, pinned plugin with attacker-controlled code, potentially giving the malicious plugin the same access as the developer running the agent. 🎯 Affected: Claude Code, Codex, GitHub Copilot and Gemini CLI. 🔴 Claude Code 2.1.179 and Codex 0.146.0 are patched. GitHub Copilot remains unpatched, while Gemini CLI is deprecated and will not receive a fix. ⚠️ No CVE has been assigned. 🔗 air.security/blog-posts/plug… #Plugin4Shell #AI #CyberSecurity #RCE #SupplyChain #Infosec

Sep 21, 2026 · 7:34 AM UTC

90
Sort replies: Relevant Recent Liked