[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fUKtagcgGty2w1rhGbzKo5tup9enpkcpxNiYHklSuAqc":3},{"article":4,"iocs":50},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":32,"category":33,"article_tags":37},"6128f6ae-6d95-456d-ade3-058e942f1959","Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents","plugin4shell-lets-repository-owners-swap-pinned-plugin-code-across-four-ai-codin-68651e","A flaw in four widely used AI coding agents lets someone who controls a plugin's code repository swap the plugin an agent installs for a malicious one, even when the agent locked that plugin to a specific reviewed version, security firm Air Security said on Thursday. The firm said Anthropic has patched the flaw in Claude Code 2.1.179 and OpenAI in Codex 0.146.0, that GitHub Copilot has no","A vulnerability dubbed Plugin4Shell affects four major AI coding agents, allowing repository owners to substitute malicious code for legitimate, pinned plugins. This occurs even when the agent has locked the plugin to a specific reviewed version. While Anthropic and OpenAI have released patches, GitHub Copilot remains unfixed, and Google will not patch the retiring Gemini CLI. The attack exploits how some Git hosts permit branch names that mimic commit hashes, enabling the agent to install different code while reporting the pinned version.","Flaw in AI coding agents allows repo owners to swap pinned plugin code for malicious versions.","Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents Swati KhandelwalSep 18, 2026Vulnerability \u002F Artificial Intelligence A flaw in four widely used AI coding agents lets someone who controls a plugin's code repository swap the plugin an agent installs for a malicious one, even when the agent locked that plugin to a specific reviewed version, security firm Air Security said on Thursday. The firm said Anthropic has patched the flaw in Claude Code 2.1.179 and OpenAI in Codex 0.146.0, that GitHub Copilot has no fix, and that Google will not patch the Gemini CLI, which it is retiring. The agents install add-ons called plugins from online marketplaces. To stay safe, a marketplace locks each plugin to a single reviewed version by its commit hash, a long string that identifies an exact snapshot of the code. Air found that the agents fetch that snapshot but never check that the code they end up with actually matches it. A branch is a named line of code in a repository. On a code host that lets someone create a branch whose name is made to look like the commit hash, the owner of a plugin's repository can point that name at different code. The agent then installs the different code while still reporting that it is on the locked version. Because a plugin runs with the same access as the person using the agent, the swapped code can access that person's files, saved credentials, and the systems they can log in to, Air said. The trick does not work everywhere. GitHub does not allow branch or tag names that look like commit hashes, according to GitHub's documentation, so a plugin installed from a GitHub repository is not exposed to this branch trick. Air says the trick works on hosts that permit such names, such as Bitbucket or a company's own git server, which these agents also support. The Hacker News checked the marketplaces the agents ship with on September 18 and found that every plugin in Anthropic's community catalog, and in the default catalogs for Claude Code and Copilot, points to a GitHub repository. The Gemini CLI is attacked a different way. Instead of a branch shaped like the hash, Air says its installer can be tricked by a repository whose main branch is named FETCH_HEAD, and GitHub's rule against hash-shaped names does not clearly block that name. So it is not established that installing a Gemini CLI plugin from GitHub avoids the flaw, and the Gemini CLI is the agent Air says will not be fixed. What would make the attack need no action from the victim is background auto-update, which lets an agent refresh installed plugins on its own, so a plugin someone already trusts can be replaced without a prompt. Air says this runs by default in Claude Code and Codex. But auto-update is on by default only for the agents' own built-in marketplaces, which are hosted on GitHub, and is off or optional for outside ones, according to Anthropic's and GitHub's documentation. So a reader who installs plugins only from the agents' default, GitHub-based marketplaces is not exposed to the branch-name version of the attack, on Air's and GitHub's own account of how it works. Air says it built a working test attack against all four agents in May and told the vendors in June. As of September 18, no CVE identifier had been assigned, and none of the four vendors had published a security advisory for the flaw, checks by The Hacker News found, and there is no sign it has been used in a real attack. The Hacker News reproduced the underlying Git behavior in a local test, and OpenAI's own public fix describes the same bug: Git \"can interpret a requested commit SHA as a branch name,\" the company wrote, which can make a plugin source \"materialize a different commit than the one it pinned.\" That change shipped in Codex 0.146.0. Because each agent checks the lock on the user's own machine, not at the marketplace, no marketplace can fix this for users — the fix has to ship in the agent itself. Where each agent stands: Agent Status What to do Anthropic Claude Code Fixed, Air says, in 2.1.179 Update to 2.1.179 or later OpenAI Codex Fixed in 0.146.0 Update to 0.146.0 or later GitHub Copilot No fix, Air says No patch available Google Gemini CLI Will not be fixed, Air says Move to Antigravity, Air and Google say The sources do not say whether updating an affected agent removes a plugin that was already swapped, or only stops future swaps. Anthropic's release notes for 2.1.179 do not mention the fix, and the account that it is fixed in is Air's. For Copilot, Air says it told Microsoft in June and that no fix has shipped. Copilot can install plugins from hosts other than GitHub, which is where Air says the risk sits. Google stopped serving the consumer Gemini CLI in June and has been pointing users to Antigravity, its newer agent, which Air says this attack cannot reach. Google has also said that enterprise access to the Gemini CLI will continue with updates. Whether a fix for this flaw is among them is not clear. The same researchers have tested agent add-ons before. In June, The Hacker News covered Air's test in which a fake skill passed security scanners and reached about 26,000 agents by changing an external link after the review had cleared it. Plugin4Shell moves that idea from a swapped link to a swapped plugin sitting behind a version lock. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  artificial intelligence, Supply Chain, Vulnerability ⚡ Top Stories This Week OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure Claude Used to Automate Exploitation and Data Theft Across Multiple Victims Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6 Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks When the Whole Company Adopts AI: What It Does to Your SOC Your Critical Vulnerabilities Might Not Be Your Biggest Risk What It Took to Reach 1 Billion Build Manifests US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries Why Are So Many Security Professionals Keeping Breaches Quiet? The Economics of Dwell Time and Why AI Native SIEM Changes the Equation ⭐ Featured Resources Get the eBook: Map Enterprise AI Risk Across the Full Lifecycle Give SOC Analysts Visibility Into 90% of Attacks Within 60 Seconds Benchmark Your SOC's AI Adoption With the 2026 Security Operations Report Register for LDR516: Strategic Vulnerability and Threat Management at SANS DC Metro","https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fplugin4shell-lets-repository-owners.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEizNK9maRYTbrRVwr9_9b7Sm_IizPdRJh0AbH1GtKU1BNPrcxJydnUdRQxRxauE5p1ejpfk4ihANpP7HAoXbRCDD1Pu-ZZD1dnfzLFjysOSJm7gGRKYrkUjxVF-tX-0neJMQtN87iyk1DRD70hKKtFU_J6idWK4aoZr3k4DAz4q8pkjTfKTX10Vttaiwag\u002Fs1600\u002Fcoding-agents.jpg","2026-09-18T11:01:01+00:00","2026-09-18T14:00:20.835632+00:00",8,[18,21,23,25,27,30],{"name":19,"type":20},"Claude Code","product",{"name":22,"type":20},"Codex",{"name":24,"type":20},"GitHub Copilot",{"name":26,"type":20},"Gemini CLI",{"name":28,"type":29},"Anthropic","vendor",{"name":31,"type":29},"OpenAI","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":32,"icon":34,"name":35,"slug":36},null,"Vulnerabilities","vulnerabilities",[38,43,45],{"category":39},{"id":40,"icon":34,"name":41,"slug":42},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":44},{"id":32,"icon":34,"name":35,"slug":36},{"category":46},{"id":47,"icon":34,"name":48,"slug":49},"839da5c1-3c34-47e2-9499-f7201640e3ac","AI Security","ai-security",[]]