logoalt Hacker News

Plugin4Shell – Zero Click RCE Vulnerability found in top four coding agents

11 pointsby fishthethisyesterday at 8:05 PM2 commentsview on HN

Comments

SahAssaryesterday at 9:45 PM

This sounds very AI written and buries the lede, but my understanding is if you control the repo in a way that you can set the default branch state for a git repo and get a victim to install a plugin with the same git sha as that branch state you can RCE them?

Pretty bad for a package manager, but this seems like something I would unfortunately expect from a harness/agent.

devmoryesterday at 9:39 PM

This article is either AI-authored slop, or handwritten by people too mired in slop to write normal prose anymore.

It’s painful to read, regardless of the topic’s impact.