Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents

A flaw in four widely used AI coding agents lets someone who controls a plugin’s code repository swap the plugin an agent installs for a malicious one, even when the agent locked that plugin to a specific reviewed version, security firm Air Security said on Thursday.

The firm said Anthropic has patched the flaw in Claude Code 2.1.179 and OpenAI in Codex 0.146.0, that GitHub Copilot has no

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Attack Update: Top 5 Attack-IPs auf doode.info – 07.08.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 89.167.35.212 — 714 requests (recent log) 144.76.19.72 — 647 requests (recent log) 88.99.244.56 — 519 requests (recent

METR and Redwood Offer Holy %^ Postmortem of the HuggingFace Hack

METR and Redwood Offer Holy %^ Postmortem of the HuggingFace Hack Source: Hacker News

Ask HN: Why were OpenAI, Claude, and Grok simultaneously down?

Ask HN: Why were OpenAI, Claude, and Grok simultaneously down? Source: Hacker News