Plugin4Shell – Zero Click RCE Vulnerability found in top four coding agents

11 pointsposted 9 hours ago
by fishthethis

2 Comments

SahAssar

8 hours ago

This sounds very AI written and buries the lede, but my understanding is if you control the repo in a way that you can set the default branch state for a git repo and get a victim to install a plugin with the same git sha as that branch state you can RCE them?

Pretty bad for a package manager, but this seems like something I would unfortunately expect from a harness/agent.

devmor

8 hours ago

This article is either AI-authored slop, or handwritten by people too mired in slop to write normal prose anymore.

It’s painful to read, regardless of the topic’s impact.