Plugin4Shell – Zero Click RCE Vulnerability found in top four coding agents

fishthethis 11 points 2 comments September 17, 2026
www.air.security · View on Hacker News

Discussion Highlights (2 comments)

devmor

This article is either AI-authored slop, or handwritten by people too mired in slop to write normal prose anymore. It’s painful to read, regardless of the topic’s impact.

SahAssar

This sounds very AI written and buries the lede, but my understanding is if you control the repo in a way that you can set the default branch state for a git repo and get a victim to install a plugin with the same git sha as that branch state you can RCE them? Pretty bad for a package manager, but this seems like something I would unfortunately expect from a harness/agent.

Semantic search powered by Rivestack pgvector
7,105 stories · 65,136 chunks indexed