HackerFeeds

CyberSecurity News

Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents

The Hacker News
· September 18, 2026

AI summary

A vulnerability has been discovered in four popular AI coding agents, allowing an attacker who controls a plugin's code repository to replace a pinned plugin with a malicious one. This can occur even if the agent has locked the plugin to a specific reviewed version. The issue has been patched by Anthropic in Claude Code version 2.1.179 and by OpenAI in Codex version 0.146.0. However, GitHub Copilot has not patched the flaw. The security firm Air Security disclosed the vulnerability, which affects the ability of the AI coding agents to ensure the integrity of installed plugins.

Read the full article at The Hacker Newsthehackernews.com/2026/09/plugin4shell-lets-repository-owners.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.