Ethical Hacking News
Four AI coding agents have been exposed to a critical vulnerability that could allow malicious actors to replace legitimate plugins with their own malicious counterparts. The vulnerability, discovered by Air Security, highlights the need for greater vigilance in the use of AI-powered tools and the importance of regular updates and patches to address such vulnerabilities. As a result, users are advised to update to the patched versions of the affected agents, including Anthropic's Claude Code and OpenAI's Codex, and to remain vigilant in the face of emerging security threats.
Four widely used AI coding agents - Claude Code, OpenAI in Codex, GitHub Copilot, and Google Gemini CLI - have a critical vulnerability that allows malicious actors to replace legitimate plugins. The vulnerability is attributed to the fact that the agents do not adequately verify the authenticity of the plugins they install. The attack mechanism relies on manipulating the agent's locking mechanism, which can be exploited by attackers who use platforms that permit specific branch or tag names. Some agents, such as GitHub Copilot, do not have a fix in place, while others have patched the issue. Users are advised to update to the patched versions of the affected agents, and vendors should prioritize transparency and communication regarding security issues and their resolution.
The cybersecurity landscape has witnessed a significant breach, with a recent discovery revealing a critical vulnerability in four widely used AI coding agents. Plugin4Shell, a platform designed to facilitate repository owners in swapping pinned plugin code across four AI coding agents, has been found to contain a flaw that could allow malicious actors to replace legitimate plugins with their own malicious counterparts.
The vulnerability, disclosed by Air Security, a cybersecurity firm, is attributed to the fact that the four AI coding agents - Claude Code, OpenAI in Codex, GitHub Copilot, and Google Gemini CLI - do not adequately verify the authenticity of the plugins they install. This allows an attacker who controls a plugin's code repository to swap a legitimate plugin with a malicious one, even when the agent is locked to a specific reviewed version. The agent's locking mechanism, which relies on a long string of code known as a commit hash, is vulnerable to manipulation, as the attackers can create a branch with a name that matches the commit hash.
As a result, the malicious code can be installed alongside the legitimate code, potentially allowing the attacker to access sensitive information, including files, saved credentials, and systems that the user can log in to. The vulnerability is further exacerbated by the fact that some agents, such as GitHub Copilot, do not have a fix in place, while others, such as Anthropic's Claude Code and OpenAI's Codex, have patched the issue.
The attack mechanism relies on the fact that each agent checks the lock on the user's machine, rather than the marketplace, and that some marketplaces, such as those hosted on GitHub, do not allow branch or tag names that resemble commit hashes. This limitation, however, can be exploited by attackers who use platforms that permit such names, such as Bitbucket or a company's own Git server.
The discovery of this vulnerability highlights the need for greater vigilance in the use of AI-powered tools and the importance of regular updates and patches to address such vulnerabilities. In this case, the affected agents have been identified as Claude Code, OpenAI in Codex, GitHub Copilot, and Google Gemini CLI, with Anthropic's Claude Code and OpenAI's Codex having patched the issue.
In response to the vulnerability, Air Security has recommended that users update to the patched versions of the affected agents. However, the vulnerability highlights the need for greater transparency and communication from vendors regarding security issues and their resolution.
In conclusion, the discovery of this vulnerability in four widely used AI coding agents underscores the importance of cybersecurity awareness and the need for regular updates and patches to address emerging vulnerabilities.
Related Information:
https://www.ethicalhackingnews.com/articles/Four-AI-Coding-Agents-Exposed-to-a-Critical-Vulnerability-What-You-Need-to-Know-ehn.shtml
https://thehackernews.com/2026/09/plugin4shell-lets-repository-owners.html
Published: Fri Sep 18 10:07:39 2026 by llama3.2 3B Q4_K_M