AI coding agents plugin pinning bypass security flaw
Vulnerability
Summary
Hide ▲
Show ▼
Plugin pinning bypass in four AI coding agents lets a repository owner swap a supposedly reviewed plugin for malicious code, turning a trusted add-on into a code-execution path. The swapped plugin can reach files, saved credentials, and the systems the user can log in to. Anthropic patched Claude Code 2.1.179 and OpenAI patched Codex 0.146.0, while GitHub Copilot has no fix and Gemini CLI will not be patched.
Related Happenings
SOC guidance to tune AI-agent detections and hunt exposure paths
Defensive Guidance
H score11
First: 12.09.2026 13:24
Last: 12.09.2026 13:24
Sources 1
About this happening:
SOC teams using AI tools and agents are being told to tune legacy detections and hunt risky AI activity because routine agent work is flooding alert queues while expos...
SOC guidance to tune AI-agent detections and hunt exposure paths
Defensive GuidanceAbout this happening: SOC teams using AI tools and agents are being told to tune legacy detections and hunt risky AI activity because routine agent work is flooding alert queues while expos...
AIR Security launches AIR firewall for enterprise AI-agent supply chains
Security Tool/Service
H score18
First: 03.09.2026 15:00
Last: 03.09.2026 15:00
Sources 1
About this happening:
AIR Security emerged from stealth with AIR, a firewall for AI agents that evaluates add-ons before and after deployment to reduce supply-chain risk. The product target...
AIR Security launches AIR firewall for enterprise AI-agent supply chains
Security Tool/ServiceAbout this happening: AIR Security emerged from stealth with AIR, a firewall for AI agents that evaluates add-ons before and after deployment to reduce supply-chain risk. The product target...
Ghostjacking AI hijacking attack using trusted logs and alerts
Technical Analysis
H score30
First: 10.08.2026 15:59
Last: 10.08.2026 15:59
Sources 1
About this happening:
Researchers demonstrated Ghostjacking, an AI hijacking technique that turns trusted logs, alerts, and agent inputs into a command channel for agentic tools, creating risk...
Ghostjacking AI hijacking attack using trusted logs and alerts
Technical AnalysisAbout this happening: Researchers demonstrated Ghostjacking, an AI hijacking technique that turns trusted logs, alerts, and agent inputs into a command channel for agentic tools, creating risk...
Ghostjacking attack chain abuses AI agents' trusted access to bypass firewalls
Technical Analysis
H score39
First: 10.08.2026 13:45
Last: 10.08.2026 13:45
Sources 1
About this happening:
Tenet Security researchers demonstrated Ghostjacking at DEF CON 2026 in Las Vegas on August 9, showing that a fake bug report can hijack AI coding assist...
Ghostjacking attack chain abuses AI agents' trusted access to bypass firewalls
Technical AnalysisAbout this happening: Tenet Security researchers demonstrated Ghostjacking at DEF CON 2026 in Las Vegas on August 9, showing that a fake bug report can hijack AI coding assist...
ChatGPT Workspace Agents CSRF AgentForger security flaw
Vulnerability
H score40
First: 24.07.2026 14:53
Last: 24.07.2026 14:53
Sources 1
About this happening:
OpenAI's ChatGPT Workspace Agents faced a cross-site request forgery (CSRF) flaw that let a single phishing link create and deploy an attacker-controlled agent inside...
ChatGPT Workspace Agents CSRF AgentForger security flaw
VulnerabilityAbout this happening: OpenAI's ChatGPT Workspace Agents faced a cross-site request forgery (CSRF) flaw that let a single phishing link create and deploy an attacker-controlled agent inside...
Timeline
-
18.09.2026 14:01 2 articles · 4h ago
Air Security reports plugin pinning bypass in four AI coding agents
Initial DisclosureAir Security said a flaw in four AI coding agents lets a plugin repository owner swap a locked plugin for malicious code by making a branch or repository name mimic a commit SHA or FETCH_HEAD, allowing the replaced plugin to access the user's files, saved credentials, and logged-in systems. Air said it built a working test attack in May and notified vendors in June; as of September 18, Anthropic had patched Claude Code 2.1.179, OpenAI had patched Codex 0.146.0, GitHub Copilot had no fix, and Google would not patch Gemini CLI.
Show sources
- Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents — thehackernews.com — 18.09.2026 14:01
- Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents — thehackernews.com — 18.09.2026 14:01