← Founder Notes
Archive ·

A zero-click remote code execution flaw called plugin4shell hit claude code, codex, copilot, and…

01:47 ISTby Yethikrishna R

a zero-click remote code execution flaw called plugin4shell hit claude code, codex, copilot, and gemini cli on september 18 through malicious plugin updates, no click or approval needed. the attack surface moved from the model to the update path. every coding agent is now a supply chain.

Share

Embed this note

<iframe src="https://founder.myndlabs.tech/notes/embed/a-zero-click-remote-code-execution-flaw-called-DdcRi3VF49r" width="480" height="420" style="border:0;max-width:100%" loading="lazy" title="A zero-click remote code execution flaw called plugin4shell hit claude code, codex, copilot, and…"></iframe>

Original

More notes