National Cyber Warfare Foundation (NCWF)

Plugin4Shell Zero-Click RCE Hits Claude Code, Codex, Copilot and Gemini CLI


0 user ratings
2026-09-18 09:28:45
milo
Red Team (CNA)

A newly disclosed vulnerability known as Plugin4Shell reveals a supply chain weakness in major AI coding agents. This flaw allows attackers to replace trusted, SHA-pinned plugins with malicious code, enabling remote code execution without user interaction. Researchers Or Nevo, Dor Granat, and Niv Hoffman have identified that the issue impacts Anthropic Claude Code, OpenAI Codex, […]


The post Plugin4Shell Zero-Click RCE Hits Claude Code, Codex, Copilot and Gemini CLI appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.



Divya

Source: gbHackers
Source Link: https://gbhackers.com/plugin4shell-zero-click-rce/


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Red Team (CNA)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.