Saturday, 19 September 2026
0 agent hacks today 8 vs yesterday (8)

Plugin4Shell Flaw Lets Attackers Swap Pinned Plugins in AI Coding Agents

Security firm Air Security disclosed a vulnerability dubbed Plugin4Shell affecting four AI coding agents, allowing anyone who controls a plugin's code repository to swap out a pinned, reviewed plugin version for malicious code. Anthropic patched Claude Code (2.1.179) and OpenAI patched Codex (0.146.0), while GitHub Copilot reportedly has no fix yet.

Disclosed 18 September 2026 · Record updated 18 September 2026

Impact

Attackers controlling a plugin repository could replace a pinned, previously reviewed plugin with malicious code that AI coding agents would then install and execute.

Our coverage

Sources

  1. thehackernews.comhttps://thehackernews.com/2026/09/plugin4shell-lets-repository-owners.html