FlagThis — Daily Cybersecurity Intelligence Briefing

FILTERING BY: CLEAR FILTER

Plugin4Shell and LangGraph Vulnerability Chains: Critical RCE in GitHub Copilot, Claude Code, and Gemini CLI

The discovery of "Plugin4Shell" and associated LangGraph vulnerability chains introduces a critical zero-click Remote Code Execution (RCE) vector targeting AI-driven development environments. By exploiting plugin marketplaces and orchestration logic, attackers inject malicious instructions into plugin metadata or retrieved grounding context. This triggers semantic integrity failures and agentic memory exploitation, enabling CVE-2026-35603 privilege escalation. The vulnerability allows adversaries to hijack the full permissions of developers within GitHub Copilot, Claude Code, and Gemini CLI, facilitating unauthorized access to proprietary source code, corporate credentials, and internal enterprise systems through autonomous, unintended tool execution.


LINK COPIED TO CLIPBOARD