
Plugin4Shell Vulnerability Affects Major AI Coding Agents
CybersecurityVulnerabilitiesArtificial IntelligenceSoftware Security
A critical security vulnerability named Plugin4Shell affects multiple AI coding agents including Claude Code, OpenAI Codex, GitHub Copilot, and Gemini CLI. The vulnerability causes coding agents to automatically load and execute malicious code. Anthropic and OpenAI have released patches for their respective products. GitHub has not responded to the security issue.