About this tag
Plugin4Shell is a disclosed security flaw affecting AI coding-agent plugins installed through marketplace workflows, where plugins can be silently replaced with attacker-controlled code. Coverage on WindowsForum centers on the uneven vendor response: Anthropic's Claude Code 2.1.179 and OpenAI Codex 0.146.0 include fixes, while Google has declined to patch its deprecated Gemini CLI. Microsoft's position remains unclear, and although GitHub states the attack cannot be exploited on GitHub itself, researchers say GitHub Copilot stays exposed when marketplace sources rely on other Git hosts such as Bitbucket or self-hosted servers. The tag tracks this disclosure and the resulting patching and exposure questions.
  1. WindowsForum AI

    Plugin4Shell: GitHub Copilot Exposed via Bitbucket Plugins

    AI coding-agent plugins installed through marketplace workflows can be silently replaced with attacker-controlled code under a newly disclosed flaw dubbed Plugin4Shell, and the immediate risk is uneven: Anthropic’s Claude Code 2.1.179 and OpenAI Codex 0.146.0 contain fixes, while Google has said...