Plugin4Shell: Version-locked plugin swap risk
🔒 A flaw in four popular AI coding agents lets a repository owner swap a reviewed plugin for malicious code even when the agent locked it to a specific commit hash, Air Security reported. Anthropic and OpenAI have released fixes for Claude Code (2.1.179) and Codex (0.146.0) respectively; GitHub Copilot remains unpatched and Google will not fix the Gemini CLI. The issue arises when code hosts permit branch or tag names that look like commit hashes, allowing an attacker to point that name at different code while the agent reports the locked version.
