1 entry tagged Plugin4Shell. All writing.
TECHNOLOGY · SEPTEMBER 22, 2026 Plugin4Shell: A Pin Is Not a Verification AIR Security disclosed "Plugin4Shell" on September 17, 2026 — a zero-click flaw in Claude Code, OpenAI Codex, GitHub Copilot and Gemini CLI that let a hijacked git branch silently swap in different code than the one a plugin manifest had pinned by commit hash. OpenAI's own four-line patch note describes the whole bug: nobody checked what git actually checked out.