Source · DiggingBeagle record

Plugin4Shell - Zero Click RCE Vulnerability found in top 4 most popular coding agents

Primary Plugin4Shell technical disclosure describing the plugin SHA-pinning bypass, the SHA-shaped default-branch and FETCH_HEAD variants, zero-click background-update path, affected coding agents and vendor remediation status.

Published
Sep 17, 2026
Accessed
Sep 19, 2026
Publisher
AIR Security

Each support, contradiction or context label applies to a cited Claim, not to a whole Case.

Source record

Primary Plugin4Shell technical disclosure describing the plugin SHA-pinning bypass, the SHA-shaped default-branch and FETCH_HEAD variants, zero-click background-update path, affected coding agents and vendor remediation status.

Read the original source ↗

Claim-level citations (8)

Cite this record

DiggingBeagle. “Plugin4Shell - Zero Click RCE Vulnerability found in top 4 most popular coding agents.” Published Sep 17, 2026 · Accessed Sep 19, 2026. https://diggingbeagle.com/sources/plugin4shell-zero-click-rce-vulnerability-found-in-top-4-most-popular-coding-age/

Citation guidance

Why this archive exists

The source matters after the headline fades.

DiggingBeagle is a non profit research project documenting AI security incidents, agent failures, vulnerabilities and AI-assisted operations. A case keeps its claims beside the sources that support, contest or limit them. Later updates stay visible, so a reader can see when the account changed.

We publish case reconstructions, dated reporting and analysis across records. Each has a different evidentiary role. About the project and our methodology explain how the work is reviewed.