Tech article
Plugin4Shell – Zero Click RCE Vulnerability found in top four coding agents
No preview is available. Read the original article for the full story.
Hacker News | Sep 17, 2026 | fishthethis
Automated excerpt
Plugin4Shell is the story of that boundary failing. It is a plugin SHA-pinning bypass: the agent checks out the exact commit the marketplace pinned but never verifies it landed there, so an attacker who controls the plugin's repo makes the checkout resolve to malicious code while the pin still looks honored. Every install is pinned to aaa... aaa, the reviewed, trusted version. The pinned commit itself can stay untouched.
Selected automatically from source text; not independently written or fact-checked. Read the original for full context.