Security/demo/2026-09-17

Plugin4Shell vulnerability bypasses SHA-pinning in AI coding agents

A security vulnerability, dubbed Plugin4Shell, has been discovered that bypasses SHA-pinning, a critical safety mechanism, in AI coding agents. Reported by shattered.io and thenextweb.com, this flaw allows the circumvention of security checks. Shattered.io specifically notes that four AI coding agents are affected by this bypass.

2 articles from 2 outlets covered this story. The underlying claim is sourced from a demo.

What do all outlets agree on?

2 outlets covered “Plugin4Shell vulnerability bypasses SHA-pinning in AI coding agents”. All of them report the following:

  • Plugin4Shell is a security vulnerability
  • It affects AI coding agents
  • It bypasses a security mechanism

Which outlets covered this?

All 2 articles found on this story, grouped by the stance of the piece. Every link goes to the original publisher.

What related stories are there?

Which companies does this involve?

Get the week in AI in one email

What happened, which outlets reported it, and where their coverage differed. One issue a week.

The first issue hasn’t gone out yet. Subscribe and it’s the one you’ll get.

We’ll send the digest and nothing else. One-click unsubscribe. Privacy.