Zranitelnost v AI programovacích agentech umožňuje vzdálené spuštění kódu bez interakce

16 zdroje
  • Plugin4Shell obchází SHA-pinning u všech hlavních AI programovacích agentů, což útočníkům umožňuje tiše nahradit důvěryhodné pluginy škodlivými, uvádějí výzkumníci ze společnosti Air.
  • Anthropic a OpenAI chybu opravily, ale Google odmítl opravit zastaralé Gemini CLI a Microsoft zatím Copilot neopravil.
  • Podle Microsoftu používá Copilot téměř 90 % firem z žebříčku Fortune 500 a výzkumníci z Air tvrdí, že opatření GitHubu jsou nedostatečná.
Zdroje (16)
  1. 1 AI coding agents' 0-click RCE flaw could hand attackers keys to the kingdom www.theregister.com
  2. 2 Plugin4Shell - Zero Click RCE Vulnerability found in top 4 ... www.air.security
  3. 3 Black Hat 2026: Critical Flaws Found in Anthropic, Google ... www.esecurityplanet.com
  4. 4 Same Flaw Found in Claude Code, Codex, Gemini CLI and GitHub Copilot www.theinformation.com
  5. 5 Market Alert: AI coding agents' 0-click RCE flaw could hand ... jafdip.com
  6. 6 Plugin4Shell - Zero Click RCE Vulnerability found in top 4 ... vuink.com
  7. 7 GitHub just added Claude and OpenAI Codex to Copilot! www.reddit.com
  8. 8 Plugin4Shell – Zero Click RCE Vulnerability found in top four ... hackerfeeds.com
  9. 9 Claude and Codex now available for Copilot Business & ... github.blog
  10. 10 AI coding agents' 0-click RCE flaw could hand attackers k ... www.imtr.net
  11. 11 Claude Code 2.1.204, Copilot 1.0.69, Codex 0.143.0 · ... github.com
  12. 12 Plugin4Shell: Zero-Click RCE Found in Claude Code, Codex ... stackfutures.com
  13. 13 Comparing OpenAI Codex CLI, GitHub Copilot, and ... ai.plainenglish.io
  14. 14 GuardFall: Shell Injection Bypass Defeats AI Coding Agent ... labs.cloudsecurityalliance.org
  15. 15 GitHub previews support for Claude and Codex coding ... www.infoworld.com
  16. 16 When prompts become shells: RCE vulnerabilities in AI agent ... www.microsoft.com