The record
Written from the 1 report below. Nothing here is unsourced.
- A flaw exists in four AI coding agents where attackers can bypass version pinning for plugins, allowing the installation of malicious code.
- By creating branch names that mimic commit hashes on certain Git hosting services, repository owners can deceive agents into installing different code versions while reporting the locked version as verified.
- While vendors like Anthropic and OpenAI have issued patches, GitHub Copilot remains unpatched and Google's Gemini CLI will not receive a fix.
- Users are advised to rely on default, GitHub-hosted marketplaces where the specific branch-based attack vector is mitigated.
What to watch next
- Verification of whether agent updates remove already-swapped malicious plugins
- Potential exploitation of the branch-name vulnerability on non-GitHub repositories
- Future security updates or mitigations for GitHub Copilot
Coverage1
1 report
English national1
All filed from India
Named United States · Antigravity · Claude Code · Codex · Copilot · Gemini CLI · Air Security · Anthropic · GitHub · Google · OpenAI
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
