| |
Plugin4Shell – Zero Click RCE Vulnerability found in top four coding agents
Plugin4Shell is a zero-click remote code execution vulnerability affecting the four major AI coding agents (Claude Code, Codex, GitHub Copilot, and Gemini), exploiting a flaw in how these agents verify plugin authenticity through SHA pinning. The vulnerability allows attackers to swap trusted plugins with malicious ones that automatically install without user interaction, giving them full access to an employee's machine and enterprise systems. This marks the first major supply chain attack in the AI agent ecosystem, affecting millions of agents using open community marketplaces for plugin installation.
Read Full Article →
← More Tech news