Global Edition
Global Edition
UK Edition
EU Edition
US Edition

Understand the story, not the spin.

Markets

AI Coding Agents Vulnerable to Plugin Code Swap Attack

Published 18 September 2026

Security researchers have identified a critical vulnerability in four major AI coding agents that allows attackers to swap trusted plugin code for malicious versions, potentially granting access to a developer's files, credentials, and connected systems. The flaw, dubbed Plugin4Shell, was disclosed by the security firm Air Security on September 18, 2026. The vulnerability exploits a flaw in how the agents verify pinned plugin versions. AI coding agents install plugins from online marketplaces and lock them to a specific, reviewed version using a commit hash, a unique identifier for a code snapshot. Air Security found that the agents fetch the code but do not verify that the checkout actually matches the pinned hash. On code hosting platforms that allow branch names to mimic commit hashes, a repository owner can point a similarly named branch at different code. The agent then installs the malicious code while still reporting it is using the trusted, locked version. The attack is particularly dangerous because it can be zero-click.

0:00 / 0:00