Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Security Flaw in AI Coding Agents Allows Malicious Plugin Swaps

Security Flaw in AI Coding Agents Allows Malicious Plugin Swaps

Posted on September 18, 2026 By CWS

A significant security vulnerability has been uncovered in four popular AI coding agents, allowing malicious actors to substitute legitimate plugins with harmful ones. This issue persists even when an agent appears to lock a plugin to a specific, reviewed version, as reported by cybersecurity firm Air Security on Thursday.

Details of the Vulnerability

Air Security identified that the agents affected include Anthropic’s Claude Code, OpenAI’s Codex, GitHub’s Copilot, and Google’s Gemini CLI. While Claude Code has been patched in version 2.1.179 and Codex in version 0.146.0, GitHub Copilot remains without a fix. Google has decided not to address the issue in the Gemini CLI, as it plans to retire the software.

The vulnerability arises when these agents, which install software add-ons known as plugins from online marketplaces, do not verify that the installed code precisely matches the intended version. Although a marketplace ostensibly locks each plugin to a specific version using a commit hash, agents fail to check the authenticity of the fetched code.

Exploit Mechanism and Impact

The exploit involves manipulating a named line of code or branch within a repository. If a repository owner creates a branch mimicking a commit hash, they can redirect the agent to install different code while maintaining that it is the locked version. This is particularly damaging as plugins operate with the same access level as the user, potentially compromising files, credentials, and systems.

While GitHub restricts branch names that resemble commit hashes, reducing exposure to this trick, other platforms like Bitbucket do not have such limitations. Consequently, plugins sourced from these platforms remain vulnerable. A similar issue affects the Gemini CLI, where a branch named FETCH_HEAD can trick the installer, as GitHub does not block this naming convention.

Protective Measures and Current Status

To mitigate such risks, users are advised to update their agents to the latest versions where fixes are available. Anthropic and OpenAI have addressed the flaw with updates to their respective agents, while GitHub Copilot users currently have no patch available. Google recommends transitioning from Gemini CLI to its successor, Antigravity, which is purportedly safe from this exploit.

AIR Security conducted a successful test attack on all four agents in May and alerted the vendors in June. However, no Common Vulnerabilities and Exposures (CVE) identifier has been assigned, and the vendors have yet to release official security advisories.

The vulnerability underscores the importance of robust security checks within AI coding environments, as previously demonstrated in a related study where a fake skill bypassed security scanners, affecting numerous agents. With evolving threats, maintaining up-to-date software and adhering to security best practices are crucial defensive strategies.

The Hacker News Tags:AI coding, Claude Code, Gemini CLI, Git vulnerability, GitHub, OpenAI Codex, plugin swap, security flaw, Software Security

Post navigation

Previous Post: Settra Ransomware Threatens Windows Networks
Next Post: AI Agents Lead New Wave of Ransomware Threats

Related Posts

Microsoft Flags Multi-Stage AitM Phishing and BEC Attacks Targeting Energy Firms Microsoft Flags Multi-Stage AitM Phishing and BEC Attacks Targeting Energy Firms The Hacker News
ChatGPhish: Exploiting AI Web Summaries for Phishing ChatGPhish: Exploiting AI Web Summaries for Phishing The Hacker News
Human Hacker Swiftly Exploits Marimo RCE in Record Time Human Hacker Swiftly Exploits Marimo RCE in Record Time The Hacker News
Phishing Attack Evades Detection Using Fake Teams Update Phishing Attack Evades Detection Using Fake Teams Update The Hacker News
Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China The Hacker News
Salesloft OAuth Breach via Drift AI Chat Agent Exposes Salesforce Customer Data Salesloft OAuth Breach via Drift AI Chat Agent Exposes Salesforce Customer Data The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Linux Kernel Vulnerabilities Pose Root Access Risks
  • AI Agents Lead New Wave of Ransomware Threats
  • Security Flaw in AI Coding Agents Allows Malicious Plugin Swaps
  • Settra Ransomware Threatens Windows Networks
  • WordPress Patch Addresses Click2Shell Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Linux Kernel Vulnerabilities Pose Root Access Risks
  • AI Agents Lead New Wave of Ransomware Threats
  • Security Flaw in AI Coding Agents Allows Malicious Plugin Swaps
  • Settra Ransomware Threatens Windows Networks
  • WordPress Patch Addresses Click2Shell Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark