← Back to live feed · 1 stories across 1 day

Saturday, Sep 19, 2026

1 story
1
Plugin4Shell Flaw Lets Attackers Slip Malicious Code Into 4 Leading AI Coding Agents

The vulnerability enables the installation of plugin code that differs from the version reported as pinned. Attackers who control a plugin repository can slip malicious code into software "skills" after users have already downloaded them, impacting 4 leading AI coding agents.

The discovery of the flaw, identified as Plugin4Shell, underscores security risks as workers rely more heavily on AI agents and third party tools. The attack requires an attacker to have control of the plugin repository to force the agent to install code that contradicts its pinned version.

You're reading an older version of the story.
Earlier version from Saturday, Sep 19
Plugin4Shell Zero Click RCE Hits 4 AI Agents in First AI Supply Chain Flaw
5 tweets • 5 sources
See all 2 tweets →