Signal

Plugin4Shell breaks the one guarantee AI coding agent plugins were supposed to give you

Security researchers disclosed Plugin4Shell on 17 September 2026 — a zero-click vulnerability that lets a malicious plugin repository silently swap in unreviewed code across Claude Code, Codex, GitHub Copilot and Gemini CLI, breaking the SHA-pinning mechanism each tool relies on to keep installed plugins locked to a reviewed version.