AI coding agents plugin pinning bypass security flaw
Vulnerability
Summary
Hide ▲
Show ▼
Plugin pinning bypass in four AI coding agents lets a repository owner swap a supposedly reviewed plugin for malicious code, turning a trusted add-on into a code-execution path. The swapped plugin can reach files, saved credentials, and the systems the user can log in to. Anthropic patched Claude Code 2.1.179 and OpenAI patched Codex 0.146.0, while GitHub Copilot has no fix and Gemini CLI will not be patched.
Related Happenings
OpenAI Codex sandbox escape fixes in Desktop and CLI
Security Tool/Service
H score11
First: 20.09.2026 15:00
Last: 20.09.2026 15:00
Sources 1
About this happening:
OpenAI fixed Heapjack in Codex Desktop and Overpatch in Codex CLI, closing sandbox escapes that could let untrusted agent activity reach a developer's host. The fl...
OpenAI Codex sandbox escape fixes in Desktop and CLI
Security Tool/ServiceAbout this happening: OpenAI fixed Heapjack in Codex Desktop and Overpatch in Codex CLI, closing sandbox escapes that could let untrusted agent activity reach a developer's host. The fl...
Claude Opus 5 Helped Hacktron Chain Discourse libheif RCE into OpenAI Staff Account Access remote code execution flaw (CVE-2026-32882)
Vulnerability
H score39
First: 18.09.2026 15:45
Last: 18.09.2026 15:45
Sources 1
About this happening:
Discourse HEIC/HEIF upload processing is tied to CVE-2026-32882, a flaw that Discourse rates as remote code execution with an 8.8/10 severity score. The issue sits...
Claude Opus 5 Helped Hacktron Chain Discourse libheif RCE into OpenAI Staff Account Access remote code execution flaw (CVE-2026-32882)
VulnerabilityAbout this happening: Discourse HEIC/HEIF upload processing is tied to CVE-2026-32882, a flaw that Discourse rates as remote code execution with an 8.8/10 severity score. The issue sits...
SOC guidance to tune AI-agent detections and hunt exposure paths
Defensive Guidance
H score11
First: 12.09.2026 13:24
Last: 12.09.2026 13:24
Sources 1
About this happening:
SOC teams using AI tools and agents are being told to tune legacy detections and hunt risky AI activity because routine agent work is flooding alert queues while expos...
SOC guidance to tune AI-agent detections and hunt exposure paths
Defensive GuidanceAbout this happening: SOC teams using AI tools and agents are being told to tune legacy detections and hunt risky AI activity because routine agent work is flooding alert queues while expos...
AIR Security launches AIR firewall for enterprise AI-agent supply chains
Security Tool/Service
H score18
First: 03.09.2026 15:00
Last: 03.09.2026 15:00
Sources 1
About this happening:
AIR Security emerged from stealth with AIR, a firewall for AI agents that evaluates add-ons before and after deployment to reduce supply-chain risk. The product target...
AIR Security launches AIR firewall for enterprise AI-agent supply chains
Security Tool/ServiceAbout this happening: AIR Security emerged from stealth with AIR, a firewall for AI agents that evaluates add-ons before and after deployment to reduce supply-chain risk. The product target...
Ghostjacking AI hijacking attack using trusted logs and alerts
Technical Analysis
H score30
First: 10.08.2026 15:59
Last: 10.08.2026 15:59
Sources 1
About this happening:
Researchers demonstrated Ghostjacking, an AI hijacking technique that turns trusted logs, alerts, and agent inputs into a command channel for agentic tools, creating risk...
Ghostjacking AI hijacking attack using trusted logs and alerts
Technical AnalysisAbout this happening: Researchers demonstrated Ghostjacking, an AI hijacking technique that turns trusted logs, alerts, and agent inputs into a command channel for agentic tools, creating risk...
Timeline
-
18.09.2026 14:01 2 articles · 3d ago
Air Security reports plugin pinning bypass in four AI coding agents
Initial DisclosureAir Security said a flaw in four AI coding agents lets a plugin repository owner swap a locked plugin for malicious code by making a branch or repository name mimic a commit SHA or FETCH_HEAD, allowing the replaced plugin to access the user's files, saved credentials, and logged-in systems. Air said it built a working test attack in May and notified vendors in June; as of September 18, Anthropic had patched Claude Code 2.1.179, OpenAI had patched Codex 0.146.0, GitHub Copilot had no fix, and Google would not patch Gemini CLI.
Show sources
- Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents — thehackernews.com — 18.09.2026 14:01
- Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents — thehackernews.com — 18.09.2026 14:01