$ techbeacon▋
CVE & Exploits

Zero‑Click Plugin4Shell Flaw Lets Attackers Hijack Leading AI Coding Assistants

Zero‑Click Plugin4Shell Flaw Lets Attackers Hijack Leading AI Coding Assistants

A newly disclosed vulnerability dubbed Plugin4Shell enables remote code execution without any user interaction on several high‑profile AI‑driven coding tools, including Claude Code, OpenAI’s Codex, GitHub Copilot and Google’s Gemini command‑line interface.

The flaw resides in the way these agents retrieve and verify third‑party plugins. By exploiting a weakness in the supply‑chain verification process, an attacker can replace a trusted plugin—identified only by a SHA‑pinned hash—with malicious code that runs automatically when the host application loads the plugin.

Because the compromised plugins are fetched directly from the vendors' repositories, the attack can be launched without the victim taking any explicit action, earning the classification of a zero‑click remote‑code‑execution (RCE) exploit. Researchers identified that the vulnerability affects the plugin infrastructure common to the four platforms, allowing a single malicious payload to compromise multiple services that rely on the same verification logic.

AI coding assistants have become integral to software development workflows, offering autocomplete, code generation, and debugging assistance. Their extensibility through plugins has accelerated adoption but also introduced a new attack surface reminiscent of earlier supply‑chain incidents such as the SolarWinds breach. The Plugin4Shell issue underscores how the trust model for automatically downloaded components can be subverted when integrity checks are insufficiently enforced.

The vulnerability was first reported by the security group GBHackers and later examined by researchers including Or Nevo. Vendor responses have been swift: the affected companies have issued emergency patches that tighten hash verification and revoke compromised plugin identifiers. Users are advised to update to the latest versions of the affected tools and to monitor official channels for further guidance.

Industry analysts say the discovery will likely prompt a broader review of plugin ecosystems across AI services. As developers increasingly rely on these assistants, ensuring the security of the underlying supply chain will become a priority for both vendors and regulators, who may consider new standards for code‑signing and distribution of third‑party extensions.

Source: GBHackers
Threat Desk — Threat desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related