Plugin4Shell – Zero Click RCE Vulnerability found in top four coding agents
fishthethis
11 points
2 comments
September 17, 2026
Related Discussions
Found 5 related stories in 81.7ms across 7,105 title embeddings via pgvector HNSW
- Sandbox Escape Vulnerabilities Across 4 Coding Agent Vendors fogeltine · 11 pts · July 20, 2026 · 60% similar
- Pre-Authentication RCE in WordPress Core patrikg · 18 pts · July 17, 2026 · 59% similar
- I found a WordPress RCEs with GPT5.6 and $25 infosecau · 388 pts · July 20, 2026 · 55% similar
- Actively exploited sandbox RCE in all Chromium versions negura · 396 pts · September 04, 2026 · 52% similar
- Google: Attackers are using prompt injection against coding agents fourfire · 11 pts · September 09, 2026 · 51% similar
Discussion Highlights (2 comments)
devmor
This article is either AI-authored slop, or handwritten by people too mired in slop to write normal prose anymore. It’s painful to read, regardless of the topic’s impact.
SahAssar
This sounds very AI written and buries the lede, but my understanding is if you control the repo in a way that you can set the default branch state for a git repo and get a victim to install a plugin with the same git sha as that branch state you can RCE them? Pretty bad for a package manager, but this seems like something I would unfortunately expect from a harness/agent.