Back to all news
Security

Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents

The Hacker News·September 18, 2026·1 min read
Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents

A flaw in four AI coding agents allows a plugin repository owner to swap the plugin an agent installs for a malicious one, even when the agent locked the plugin to a reviewed version. Security firm Air Security disclosed the issue on Thursday. Anthropic patched it in Claude Code 2.1.179, OpenAI in Codex 0.146.0, while GitHub Copilot remains unpatched.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store