{"data":{"id":"8c167a5b-577f-4b62-a615-1637a2ecfa41","title":"Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents","summary":"A security flaw in four AI coding agents (Claude Code, Codex, GitHub Copilot, and Gemini CLI) allows someone controlling a plugin's code repository to swap in malicious code even when the agent is locked to a specific reviewed version. The vulnerability works by creating a branch with a name that looks like a commit hash (a long string identifying exact code), tricking the agent into installing different code while reporting it installed the locked version, giving the malicious code access to the user's files and credentials.","solution":"Anthropic patched the flaw in Claude Code version 2.1.179 or later. OpenAI patched it in Codex version 0.146.0 or later. GitHub Copilot has no fix available. Google will not patch Gemini CLI, which it is retiring.","labels":["security"],"sourceUrl":"https://thehackernews.com/2026/09/plugin4shell-lets-repository-owners.html","publishedAt":"2026-09-18T11:01:01.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["supply_chain"],"issueType":"news","affectedPackages":null,"affectedVendors":["Anthropic","OpenAI","Google","Microsoft"],"affectedVendorsRaw":["Anthropic","Claude Code","OpenAI","Codex","GitHub Copilot","Google","Gemini CLI"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-09-18T11:01:01.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","confidentiality"],"aiComponentTargeted":"plugin","llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}