Eigen RadarAI
Analysis

Plugin4Shell lets a marketplace pin land unverified code

The Register said Air researchers found coding agents accept a marketplace SHA pin without checking the checkout that actually landed. Anthropic and OpenAI issued fixes; Google declined a Gemini CLI change and Microsoft had not yet patched Copilot.

Artificial Intelligence··Morning
A laptop's abstract verified marketplace pin differs from the abstract folder tree in a plugin checkout on a white packing sleeve at a bright coding workbench.

The pin is checked; the tree is not

The Register’s 17 September account said marketplace listings advertise a SHA pin, and agents fetch that commit. Air’s Or Nevo, Dor Granat and Niv Hoffman argued the client never proves the working tree matches the pin. A swapped plugin can therefore execute with the trust the pin was meant to buy. The name they gave that gap is Plugin4Shell. The report treats the miss as a checkout problem, not a novel crypto break.[1]

Who shipped a fix

Air contacted four vendors in June, the Register account said. Anthropic issued a Claude Code fix at 2.1.179. OpenAI issued a Codex fix at 0.146.0. The Register wrote that Google will leave Gemini CLI unpatched and that Microsoft had not yet moved Copilot. Those vendor lines are the report’s inventory, not a ranking of whose agent is safest. Readers still only have one publisher’s write-up of the vendor replies.[1]

Auto-update makes the swap quiet

Once plugins refresh themselves, the swapped payload can arrive without a user click. The Register framed that as a remote-code path sitting on an everyday install habit. Air’s write-up, as carried there, ties the risk to agents that treat the marketplace pin as enough. However a later vendor note can still narrow who is exposed. Until a second independent outlet files the same checkout miss, the card stays on this one report.[1]

References

  1. News sourceThe RegisterPlugin4Shell swaps a pinned plugin without checking the checkout↩1↩2↩3