2 hrs ago

Plugin4Shell Hits Four Major AI Coding Assistants; Two Unpatched

Plugin4Shell Hits Four Major AI Coding Assistants; Two Unpatched
One flaw hit all four major AI coding assistants! Two are still unpatched · wionews.com

Researchers found one security flaw affecting four popular AI coding assistants.

They named the flaw Plugin4Shell.

A bad plugin update could run harmful computer code without the developer clicking anything.

The attack tricks the tool into loading dangerous code instead of the approved plugin version.

It does this by using a branch name that looks like the approved code’s fingerprint.

Anthropic fixed the problem in Claude Code.

OpenAI fixed it in Codex.

Google’s Gemini CLI is still reported to be vulnerable.

Researchers also say GitHub’s Copilot mitigation may not solve the whole problem.

Key facts

Vulnerability
Plugin4Shell
Affected tools
Anthropic’s Claude Code, OpenAI Codex, GitHub Copilot and Google’s Gemini CLI
Attack type
Zero-click plugin supply-chain attack
Exploitation method
A malicious branch name matching a 40-character commit fingerprint can be selected instead of the approved code.
Patched products
Claude Code and Codex
Unresolved products
Gemini CLI is reported as still exposed; Copilot’s mitigation is disputed by researchers.
Potential access
Compromised coding assistants may reach source code, credentials and command-execution capabilities on a developer’s machine.

Sources

Related news