‹ BackHN Continuity

Thread

Plugin4Shell – Zero Click RCE Vulnerability found in top four coding agents

11 points · 3 comments · fishthethis

Loading the complete thread in the background. This saved snapshot is available now. Refresh

  1. devmor · · focus · HN ↗
    This article is either AI-authored slop, or handwritten by people too mired in slop to write normal prose anymore.

    It’s painful to read, regardless of the topic’s impact.

  2. SahAssar · · focus · HN ↗
    This sounds very AI written and buries the lede, but my understanding is if you control the repo in a way that you can set the default branch state for a git repo and get a victim to install a plugin with the same git sha as that branch state you can RCE them?

    Pretty bad for a package manager, but this seems like something I would unfortunately expect from a harness/agent.

    1. gdor80 · · focus · HN ↗
      It’s worse than that.

      A user installs a completely safe plugin through a marketplace, the marketplace pins a vetted commit for the plugin, trusting it is safe and will stay safe. If the “safe” plugin’s repo is controlled by an attacker - he can now set the default branch to a malicious version and anyone who installs will get the malicious version, exactly what the SHA pinning exists to protect from.

      It gets worse when you consider agents auto-upgrade plugins from marketplaces. The attacker can have a new version, also benign, and open a PR to change the pinned SHA in the marketplace to the new version. Once the marketplace owner approves - do the said rug-pull and now anybody who installed the plugin gets an auto-upgrade to the malicious version.

  3. krismarker6 · · focus · HN ↗

    [dead]

  4. WaldenWuwei · · focus · HN ↗

    [dead]

  5. beyondscale-sai · · focus · HN ↗

    [dead]

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.