AI coding agents reportedly vulnerable to '0-click RCE flaw'
UKPulse Health Desk
Major AI coding agents are reportedly affected by a '0-click RCE flaw' known as Plugin4Shell, which researchers suggest could allow attackers significant access.
- AI coding agents are reportedly vulnerable to a '0-click RCE flaw' called Plugin4Shell.
- Researchers indicate that this flaw affects all major coding agents.
- The vulnerability could potentially grant attackers 'keys to the kingdom'.
A '0-click RCE flaw', dubbed Plugin4Shell, reportedly affects all major AI coding agents, according to researchers. This vulnerability could potentially allow attackers to gain significant control.
The flaw is described as a '0-click' remote code execution vulnerability, meaning it may not require user interaction to exploit. Researchers suggest that this could hand attackers 'keys to the kingdom'.