Plugin4Shell – Zero Click RCE Vulnerability found in top four coding agents
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
Plugin4Shell – Zero Click RCE Vulnerability found in top four coding agents
Unofficial Hacker News client; not affiliated with Y Combinator.
SahAssar · · focus · HN ↗
Pretty bad for a package manager, but this seems like something I would unfortunately expect from a harness/agent.
gdor80 · · focus · HN ↗
A user installs a completely safe plugin through a marketplace, the marketplace pins a vetted commit for the plugin, trusting it is safe and will stay safe. If the “safe” plugin’s repo is controlled by an attacker - he can now set the default branch to a malicious version and anyone who installs will get the malicious version, exactly what the SHA pinning exists to protect from.
It gets worse when you consider agents auto-upgrade plugins from marketplaces. The attacker can have a new version, also benign, and open a PR to change the pinned SHA in the marketplace to the new version. Once the marketplace owner approves - do the said rug-pull and now anybody who installed the plugin gets an auto-upgrade to the malicious version.