Newsletter

Five minutes. What happened, and what to do about it.

Plugin4Shell: one flaw hit Claude Code, Codex, Copilot and Gemini CLI

Help Net Security· 18 Sep

Researchers at AIR found that four major AI coding agents did not check that an installed plugin matched the version it was pinned to, so an attacker could swap in malicious code with no click from the user. Claude Code and Codex are patched. Copilot has no fix, and Gemini CLI will not get one.

  • Update Claude Code to 2.1.179 or later and Codex to 0.146.0 or later.
  • Remove plugins you do not use, and move off Gemini CLI.

Source: Help Net Security. This is our short summary of their reporting. The commentary in it and the things to do are SeedFoundry's opinion. Picture from the source, unless it is our own graphic. How we source and credit

That is fri 18 sep, all of it.

These are short summaries of other people's reporting, with our own commentary. Each story names its source and links to the original. How we source and credit