Researchers have identified a critical zero-click remote code execution vulnerability affecting all major AI coding agents, dubbed Plugin4Shell. This flaw allows attackers to execute arbitrary code on a developer's machine without any interaction or user consent. The severity stems from the agents' ability to process and execute plugins or commands triggered by malicious content.
- Plugin4Shell enables zero-click RCE across all major AI coding agents.
- Attackers can execute arbitrary code without any user interaction.
- The vulnerability highlights risks in autonomous plugin execution.
- Immediate vendor patches and agent isolation are critical defenses.