Code & Chain · Signal Desk

Plugin4Shell Flaw: Plugin Library Owners Can Swap Pinned Plugins, Affecting Four AI Coding Agents

Original sourceInfoSec Today

Summary

Security firm Air Security found a flaw dubbed Plugin4Shell that lets plugin library owners replace plugins with malicious code even when a version is pinned by commit hash, affecting four AI coding agents. Anthropic Claude Code patched it in version 2.1.179 and above, OpenAI Codex in 0.146.0 and a…

Key points

  • Any team using AI coding agents should verify versions immediately, since the flaw cannot be fixed at the marketplace level and must be defended by the agent software itself.
  • Pinned versions have long been a basic guarantee of supply chain security, and this flaw directly undermines trust in the AI agent plugin ecosystem.
  • Development teams need to upgrade to patched Claude Code and Codex versions, while Copilot and Gemini CLI users must weigh alternatives or risk.

Editorial note

This page is Code & Chain's editorial summary of public sources. It may be prepared with AI assistance and published through an automated workflow. Refer to the original sources; this content is not investment, legal, or tax advice.