Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents
Overview
A vulnerability has been discovered in four popular AI coding agents, allowing repository owners to replace legitimate plugin code with malicious versions. This issue arises even when the coding agents lock plugins to specific reviewed versions, which could expose users to harmful software. Security firm Air Security reported that Anthropic has addressed the flaw in Claude Code version 2.1.179 and OpenAI has patched it in Codex version 0.146.0. However, GitHub Copilot has not yet released a fix, leaving its users potentially at risk. This situation raises concerns about the security of AI tools that developers rely on, emphasizing the need for vigilance in maintaining software integrity.
Key Takeaways
- Affected Systems: Claude Code 2.1.179, OpenAI Codex 0.146.0, GitHub Copilot
- Action Required: Patches are available in Claude Code 2.
- Timeline: Disclosed on October 2023
Original Article Summary
A flaw in four widely used AI coding agents lets someone who controls a plugin's code repository swap the plugin an agent installs for a malicious one, even when the agent locked that plugin to a specific reviewed version, security firm Air Security said on Thursday. The firm said Anthropic has patched the flaw in Claude Code 2.1.179 and OpenAI in Codex 0.146.0, that GitHub Copilot has no
Impact
Claude Code 2.1.179, OpenAI Codex 0.146.0, GitHub Copilot
Exploitation Status
No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.
Timeline
Disclosed on October 2023
Remediation
Patches are available in Claude Code 2.1.179 and OpenAI Codex 0.146.0; GitHub Copilot has no patch available yet.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Vulnerability.