Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents
- ID
- 25976
- Status
- summarized
- Published
- 18 Sep 2026, 7:01 PM
- Fetched
- 18 Sep 2026, 11:12 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/plugin4shell-lets-repository-owners.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 8.0
- Created
- 18 Sep 2026, 11:12 PM
- Tags
- Audience
- developersvibe_codersai_agent_users
What happened
A vulnerability dubbed Plugin4Shell lets repository owners swap pinned plugin code in four AI coding agents (Claude Code, Codex, Copilot, Gemini CLI) by creating a branch named like the commit hash the agent locked to, then pointing it at malicious code. Anthropic patched it in Claude Code 2.1.179 and OpenAI in Codex 0.146.0, but GitHub Copilot has no fix and Google won't patch Gemini CLI (being retired). GitHub blocks hash-shaped branch names so GitHub-hosted plugins are safe from the branch trick, but Bitbucket and self-hosted git servers are exposed; Gemini CLI has a separate attack via a main branch named FETCH_HEAD.
Why it matters
If you use AI coding agent plugins from non-GitHub hosts (Bitbucket, internal git), update Claude Code to 2.1.179+ or Codex to 0.146.0+ immediately and audit which plugins you've installed — swapped code runs with your full file and credential access. Copilot users have no vendor fix yet, so avoid installing plugins from non-GitHub repositories. Gemini CLI users should stop installing new plugins given it will never be patched.
Discussion angle
Walk through the attack mechanism live (branch name mimicking commit hash, agent never re-verifying the fetched code) and discuss whether your team's plugin usage is GitHub-only or includes Bitbucket/internal repos — that single fact determines your exposure today.