← 返回事件
持续讨论科技

Plugin4Shell – Zero Click RCE Vulnerability found in top four coding agents

图:Hacker News

发生了什么

Plugin4Shell is a zero-click, high-severity RCE affecting all four major AI coding agents - Claude Code, Codex, Copilot, and Gemini. In this first-of-its-kind AI supply-chain attack, a trusted plugin is silently swapped for a malicious one and auto-installed past the agent's SHA pinning - a flaw no marketplace can fix, so users must update their agent.

摘要按规则整理自下方来源原文

为什么在扩散

来源