Zero-Click-Schwachstelle in führenden KI-Coding-Agenten ermöglicht Remote Code Execution

16 Quellen
  • Plugin4Shell umgeht SHA-Pinning in allen großen KI-Coding-Agenten, wodurch Angreifer unbemerkt vertrauenswürdige Plugins durch schädliche ersetzen können, so Forscher von Air.
  • Anthropic und OpenAI haben die Lücke geschlossen, doch Google lehnte eine Reparatur des veralteten Gemini CLI ab und Microsoft hat Copilot bisher nicht gepatcht.
  • Laut Microsoft nutzen fast 90 Prozent der Fortune-500-Unternehmen Copilot, und Forscher von Air halten die von GitHub beanspruchten Schutzmaßnahmen für unzureichend.
Quellen (16)
  1. 1 AI coding agents' 0-click RCE flaw could hand attackers keys to the kingdom www.theregister.com
  2. 2 Plugin4Shell - Zero Click RCE Vulnerability found in top 4 ... www.air.security
  3. 3 Black Hat 2026: Critical Flaws Found in Anthropic, Google ... www.esecurityplanet.com
  4. 4 Same Flaw Found in Claude Code, Codex, Gemini CLI and GitHub Copilot www.theinformation.com
  5. 5 Market Alert: AI coding agents' 0-click RCE flaw could hand ... jafdip.com
  6. 6 Plugin4Shell - Zero Click RCE Vulnerability found in top 4 ... vuink.com
  7. 7 GitHub just added Claude and OpenAI Codex to Copilot! www.reddit.com
  8. 8 Plugin4Shell – Zero Click RCE Vulnerability found in top four ... hackerfeeds.com
  9. 9 Claude and Codex now available for Copilot Business & ... github.blog
  10. 10 AI coding agents' 0-click RCE flaw could hand attackers k ... www.imtr.net
  11. 11 Claude Code 2.1.204, Copilot 1.0.69, Codex 0.143.0 · ... github.com
  12. 12 Plugin4Shell: Zero-Click RCE Found in Claude Code, Codex ... stackfutures.com
  13. 13 Comparing OpenAI Codex CLI, GitHub Copilot, and ... ai.plainenglish.io
  14. 14 GuardFall: Shell Injection Bypass Defeats AI Coding Agent ... labs.cloudsecurityalliance.org
  15. 15 GitHub previews support for Claude and Codex coding ... www.infoworld.com
  16. 16 When prompts become shells: RCE vulnerabilities in AI agent ... www.microsoft.com