Critical Vulnerability in Claude Code, OpenAI Codex, GitHub Copilot, and Gemini CLI
TL;DR
AI-generated
A critical vulnerability named Plugin4Shell affects coding agents like Claude Code, OpenAI Codex, and Gemini CLI by allowing malicious code execution via manipulated plugins. Anthropic and OpenAI have patched the flaw, while GitHub has not yet responded, and the consumer version of Gemini CLI remains permanently vulnerable.
Source: heise.de
Same event
- AI Agents Automatically Execute Git Malware on Startup
- Critical Vulnerability in Claude Code, OpenAI Codex, GitHub Copilot, and Gemini CLI
Discussion
Log in to join the discussion.
No comments yet. Be the first!