A single git trick beat the safety lock on four AI coding agents
The AI industry already knew attackers could poison plugin marketplaces. Its answer was to lock every plugin to one reviewed version of its code. That lock is what just broke. Researchers at Air Security published a vulnerability on Thursday that they call Plugin4Shell. It affects the four most wid…
Read the full story at The Next Web ↗
Timeline · 1 report
- 2026-09-21 12:53 · The Next Web
A single git trick beat the safety lock on four AI coding agents