Plugin4Shell Flaw Let Attackers Hijack AI Coding Agents via Broken SHA Pinning
Security researchers disclosed a vulnerability class called Plugin4Shell in September 2026, affecting four major AI coding tools: Claude Code, Codex, Gemini CLI, and GitHub Copilot. The flaw stems from a broken SHA-pinning verification process, which is meant to lock plugins to a specific, audited commit hash to prevent unauthorized code changes. Because these agents auto-update plugins silently by default, attackers could swap a legitimate plugin for malicious code after initial approval without any user interaction. Once swapped, the malicious plugin runs with the agent's full permissions, potentially exposing filesystems, credentials, CI pipelines, and cloud accounts. The vulnerability mirrors npm and PyPI supply-chain attacks but carries a larger blast radius due to the broad local and network privileges routinely granted to agentic coding tools.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in