AI Weekly Malaysia

Back to items Summaries

Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents

ID
25976
Status
summarized
Published
18 Sep 2026, 7:01 PM
Fetched
18 Sep 2026, 11:12 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/plugin4shell-lets-repository-owners.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
8.0
Created
18 Sep 2026, 11:12 PM
Tags
Audience
developersvibe_codersai_agent_users

What happened

A vulnerability dubbed Plugin4Shell lets repository owners swap pinned plugin code in four AI coding agents (Claude Code, Codex, Copilot, Gemini CLI) by creating a branch named like the commit hash the agent locked to, then pointing it at malicious code. Anthropic patched it in Claude Code 2.1.179 and OpenAI in Codex 0.146.0, but GitHub Copilot has no fix and Google won't patch Gemini CLI (being retired). GitHub blocks hash-shaped branch names so GitHub-hosted plugins are safe from the branch trick, but Bitbucket and self-hosted git servers are exposed; Gemini CLI has a separate attack via a main branch named FETCH_HEAD.

Why it matters

If you use AI coding agent plugins from non-GitHub hosts (Bitbucket, internal git), update Claude Code to 2.1.179+ or Codex to 0.146.0+ immediately and audit which plugins you've installed — swapped code runs with your full file and credential access. Copilot users have no vendor fix yet, so avoid installing plugins from non-GitHub repositories. Gemini CLI users should stop installing new plugins given it will never be patched.

Discussion angle

Walk through the attack mechanism live (branch name mimicking commit hash, agent never re-verifying the fetched code) and discuss whether your team's plugin usage is GitHub-only or includes Bitbucket/internal repos — that single fact determines your exposure today.

Top