AINewsnow

Plugin4Shell: The AI Coding Agent Supply-Chain Bug Hiding Beneath SHA Pinning

This story is from 2026-09-20. It is preserved in the archive; the latest stories are on the live feed.

What if an AI coding agent verifies the request for a specific commit, but never verifies the code it actually checked out? That is the core issue behind Plugin4Shell . AIR Security disclosed a zero-click RCE affecting Claude Code, OpenAI Codex, GitHub Copilot and Gemini CLI. The interesting part i…

Read the full story at DEV Community — AI ↗

Timeline · 1 report

  1. 2026-09-20 16:52 · DEV Community — AI
    Plugin4Shell: The AI Coding Agent Supply-Chain Bug Hiding Beneath SHA Pinning

More stories

  1. A zero-click RCE flaw in AI coding agents could have exposed enterprise systems — InfoWorld AI
  2. Plugin4Shell and NIST IR 8587, days apart: what actually authorizes an AI agent’s action? — r/AI_Agents
  3. Pay $39.99 once to put ChatGPT, Claude, Gemini, and more in a single workspace for life — Mashable AI
  4. What does AI forgetting context actually look like for you? — r/AI_Agents
  5. One prompt two models — r/AI_Agents
  6. Solving image to text captchas — r/AI_Agents
  7. Own 1 dashboard for ChatGPT, Gemini, Claude, and more for only $54.97 — Mashable AI
  8. I built a free browser tool for assembling reusable AI prompts. Would you use this instead of saved prompts? — r/PromptEngineering

Get the daily brief of stories like this at 6:30 every morning →