Get the latest tech news

Plugin4Shell – Zero Click RCE Vulnerability found in top four coding agents


Plugin4Shell is a zero-click, high-severity RCE affecting all four major AI coding agents - Claude Code, Codex, Copilot, and Gemini. In this first-of-its-kind AI supply-chain attack, a trusted plugin is silently swapped for a malicious one and auto-installed past the agent's SHA pinning - a flaw no marketplace can fix, so users must update their agent.

None

Get the Android app

Or read this on Hacker News

Read more on:

Photo of coding agents

coding agents

Photo of Plugin4Shell

Plugin4Shell

Related news:

News photo

Show HN: Graphify C# – Compiler-accurate Find Usages for coding agents

News photo

GitSpawn: Untrusted repos can execute code via AI coding agents

News photo

OKF Agent Memory – Git-native persistent memory for AI coding agents