As detailed in The Register, a critical zero-click vulnerability named "Plugin4Shell" has been discovered by Air Security researchers, impacting prominent AI coding agents and potentially exposing sensitive data and assets.The exploit targets trusted plugin marketplaces used by AI coding agents such as Anthropic's Claude Code, OpenAI's Codex, Google's Gemini CLI, and Microsoft's Copilot. This "first-of-its-kind AI supply-chain attack" bypasses the SHA-pinning mechanism designed to prevent malicious code injection. Attackers can replace benign plugins with malicious versions, leading to zero-click remote code execution when agents auto-update.While Anthropic and OpenAI have issued patches, Google has deprecated the affected Gemini CLI, and Microsoft's Copilot remains vulnerable, with GitHub stating its platform is not affected due to specific mitigation measures. Researchers warn that the attack can be scaled through marketplace takeovers, compromising the integrity of AI development tools.Source: The Register
AI/ML
New ‘Plugin4Shell’ vulnerability affects major AI coding agents
(Adobe Stock)
An In-Depth Guide to AI
Get essential knowledge and practical strategies to use AI to better your security program.
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
