Navegación

La vulnerabilidad RCE «zero-click» Plugin4Shell afecta a Claude Code, Codex, Copilot y Gemini CLI.

fuente: https://cybersecuritynews.com/plugin4shell-zero-click-rce/

Plugin4Shell is a high-severity, zero-click remote code execution vulnerability affecting major AI coding agents, including Anthropic Claude Code, OpenAI Codex, GitHub Copilot, and Google Gemini CLI.

The flaw allows a malicious plugin update to execute attacker-controlled code without requiring a user to click, approve, or reinstall anything.

Plugin4Shell targets the software supply chain behind AI agents rather than the AI models themselves. Modern coding agents can install plugins, skills, and extensions from community marketplaces.

These add-ons often inherit the same permissions as the developer running the agent, including access to local source code, cloud credentials, SSH keys, internal repositories, production systems, and secrets.

The issue lies in the way affected agents handle SHA-pinned plugin versions. Marketplace systems commonly pin a plugin to a specific Git commit hash after it has been reviewed. This is intended to ensure the agent installs the exact approved code rather than a newer or modified version.

Últimas noticias

15 DE SEPTIEMBRE, 2026

Vulnerabilidad de día cero en Cisco Secure Email Gateway explotada activamente para ejecutar código malicioso.

Cisco ha emitido una advertencia urgente sobre una vulnerabilidad de día cero que está siendo explotada activamente en sus dispositivos Secure Email Gateway; di...

Leer artículo
15 DE SEPTIEMBRE, 2026

Vulnerabilidad en AWS Systems Manager permite saltar restricciones de reenvío de puertos

Se ha detectado una vulnerabilidad crítica (CVE-2026-89049) en el AWS Systems Manager Agent que permite a atacantes autenticados evadir las restricciones de red...

Leer artículo
15 DE SEPTIEMBRE, 2026

Hackers explotan una vulnerabilidad de FortiGate SSL-VPN para atacar a un proveedor de banda ancha.

Investigadores han descubierto un servidor de preparación (staging server) expuesto y controlado por atacantes que contenía pruebas de una intrusión de gran alc...

Leer artículo