← registry

Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents

A supply chain vulnerability in four AI coding agents allowed repository owners to substitute malicious plugins for legitimate ones despite version pinning, affecting Claude, OpenAI Codex, GitHub Copilot, and JetBrains AI Assistant.

Categorysupply_chain
Severityhigh
AI systemcopilot
Sectorstechnology
Harm typessecurityfinancialreputational
Lifecycle stagedeployment
Actorvendor_thirdparty
Published2026-09-18 11:01:01

Summary is Secursion's own; full text lives at the source. Attribution preserved.