fuente: https://cybersecuritynews.com/plugin4shell-zero-click-rce/
Plugin4Shell is a high-severity, zero-click remote code execution vulnerability affecting major AI coding agents, including Anthropic Claude Code, OpenAI Codex, GitHub Copilot, and Google Gemini CLI.
The flaw allows a malicious plugin update to execute attacker-controlled code without requiring a user to click, approve, or reinstall anything.
Plugin4Shell targets the software supply chain behind AI agents rather than the AI models themselves. Modern coding agents can install plugins, skills, and extensions from community marketplaces.
These add-ons often inherit the same permissions as the developer running the agent, including access to local source code, cloud credentials, SSH keys, internal repositories, production systems, and secrets.
The issue lies in the way affected agents handle SHA-pinned plugin versions. Marketplace systems commonly pin a plugin to a specific Git commit hash after it has been reviewed. This is intended to ensure the agent installs the exact approved code rather than a newer or modified version.
Si alguna vez has usado i3 en Linux, conoces esa sensación. Ese momento en que te das cuenta de que tus ventanas pueden organizarse solas sin que tengas que mov...
Leer artículo →Kali365 convierte una cuenta legítima de Microsoft en una puerta de acceso a datos corporativos. Este kit de phishing ataca a organizaciones estadounidenses con...
Leer artículo →Tras la presentación inaugural del módulo de computación aeroespacial “NVIDIA Space-1 Vera Rubin” por parte de NVIDIA en la conferencia GTC en marzo, esta inici...
Leer artículo →