SECURITY·중요도 8·2026. 09. 18.·The Hacker News
Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents
── KO ──────────────────
AI 코딩 에이전트의 취약점으로 플러그인 코드가 악성 코드로 교체될 수 있다.
네 개의 널리 사용되는 AI 코딩 에이전트에서 플러그인의 코드 저장소를 제어하는 사람이 악성 코드로 교체할 수 있는 결함이 발견되었다. 보안 회사 Air Security는 Anthropic과 OpenAI가 해당 취약점을 패치했음을 밝혔다. GitHub Copilot의 경우 패치가 이루어지지 않았다.
── EN ──────────────────
A vulnerability in AI coding agents allows malicious plugin swaps even with locked versions.
A flaw in four widely used AI coding agents enables someone controlling a plugin's code repository to swap it for a malicious version, even if locked to a specific reviewed version. Security firm Air Security reported that Anthropic and OpenAI have patched this vulnerability. However, GitHub Copilot has not yet applied a patch.