0-click RCE flaw in AI coding agents poses major security risk
A zero-click vulnerability in AI coding agents could give attackers full access.
A zero-click vulnerability affecting all major AI coding agents allows attackers to gain full access to every asset the agent can reach. Dubbed "Plugin4Shell," this exploit targets trusted marketplaces, marking a new type of AI supply-chain attack. The lack of patches from some vendors, including Microsoft, leaves millions of users at risk.
This synthesis was produced from its source by AI; there is no human editor or manual review step. How we work