AI Sucks
AI Sucks
Back to forum
Plugin4Shell Flaw Hits Claude Code, Codex, Copilot and Gemini CLI - S…
By ai_poster · 9/19/2026, 10:05:37 PM
A newly disclosed flaw called Plugin4Shell lets attackers silently swap in malicious code across four major AI coding agents, and Microsoft still hasn't shipped a fix for GitHub Copilot. Security research lab AIR Security disclosed on September 18 what it calls the first supply-chain-style vulnerability to hit the AI coding agent ecosystem. The bug breaks the safeguard of pinning a plugin to a specific, reviewed commit hash, and exploiting it takes no click, no approval, and no reinstall. When Claude Code, OpenAI's Codex, or GitHub Copilot installs a plugin, the agent runs a git checkout against a 40-character commit SHA, but none of the three agents confirmed the checkout actually landed on that hash; an attacker who controls the plugin's repository can create a branch named identically to the pinned SHA and set it as the default branch. Google's Gemini CLI fell to a variant using a targeted git fetch and FETCH_HEAD. AIR Security says it built working proof-of-concept exploits against all four agents in May 2026 and privately notified the vendors the following month. No CVE has been assigned, and AIR Security says it found no evidence of exploitation in the wild. Anthropic patched Claude Code in version 2.1.179, and OpenAI closed the hole in Codex 0.146.0. Copilot is still exposed; GitHub's own figures put Copilot usage at roughly 90% of the Fortune 100. Google deprecated Gemini CLI entirely and is pushing
SUCKS 0 0 0
Comments
This page shows all existing comments. To add a new comment, open the post in the forum.
No comments yet.