[CYBERDIGEST]
⊞ Dashboard ⚡ Intelligence 📝 Reports 📚 Global Threats 💻 Hack Lab 🗄️ Resources ⌬ 0xJerry's Lab
📡 RSS Feed
System Online

Tag

#Plugin4Shell

articleCRITICAL 9.0

Zero-Click RCE Flaw in AI Coding Agents: Plugin4Shell

A zero-click remote code execution (RCE) flaw, dubbed Plugin4Shell, was discovered in popular AI coding agents such as OpenAI's Codex, Anthropic's Claude Code, Google's Gemini CLI, and Microsoft-owned GitHub Copilot. This vulnerability allowed attackers to execute malicious code without developer interaction by swapping a trusted plugin with a malicious one, potentially gaining a foothold in enterprise development environments. Researchers at AIR reported the flaw to the vendors, and most have released patches. Users must update their agents to mitigate the risk.

Sep 19, 20261 source