⌁AI·CYBER·BRIEF▌

#Plugin4Shell

Vulnerabilities7 min read

Plugin4Shell: AI coding agents trusted a pinned commit that wasn't there

Air Security disclosed on September 18, 2026 that Claude Code, Codex, GitHub Copilot and Gemini CLI could load attacker-controlled plugin code despite commit pinning. Two are patched, two are not.

Supply ChainAI Coding AssistantsPlugin4Shell