CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents

September 18, 2026

Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents Swati KhandelwalSep 18, 2026Vulnerability / Artificial Intelligence A flaw in four widely used AI coding agents lets someone who controls a plugin's code repository swap the plugin an agent installs for a malicious one, even when the agent locked that plugin to a specific reviewed version, security firm Air Security said on Thursday. The firm said Anthropic has patched the flaw in Claude Code 2.1.179 and OpenAI in Codex 0.146.0, that GitHub Copilot has no fix, and that Google will not patch the Gemini CLI, which it is retiring. The agents install add-ons called plugins from online marketplaces. To stay safe, a marketplace locks each plugin to…