Plugin4Shell Zero-Click RCE Hits Claude Code, Codex, Copilot and Gemini CLI

A newly disclosed vulnerability known as Plugin4Shell reveals a supply chain weakness in major AI coding agents. This flaw allows attackers to replace trusted, SHA-pinned plugins with malicious code, enabling remote code execution without user interaction. Researchers Or Nevo, Dor Granat, and Niv Hoffman have identified that the issue impacts Anthropic Claude Code, OpenAI Codex, […]

This article has been indexed from GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Read the original article: