Plugin4Shell attack affects all the major coding agents, researchers say A zero click vulnerability that allows remote code execution affects all of the major AI coding agents Anthropics Claude Code, OpenAIs Codex, Google Gemini CLI, Microsofts Copilot, and Microsoft owned GitHub Copilot and could give attackers full access to every asset and piece of data that the agent can reach, researchers say. The exploit, dubbed “Plugin4Shell,” is a “first of its kind AI supply chain attack,” according...

Read the full article at The Register