The AI industry already knew attackers could poison plugin marketplaces. Its answer was to lock every plugin to one reviewed version of its code. That lock is what just broke. Researchers at Air Security published a vulnerability on Thursday that they call Plugin4Shell. It affects the four most widely used AI coding agents. Those are […] This story continues at The Next Web
Back to Technology
Technology
September 21, 2026 at 12:53 PM
A single git trick beat the safety lock on four AI coding agents
The Next Web