vibehacker
News
Air Security ·

Plugin4Shell: SHA-pin bypass RCE hits Claude Code, Codex, Copilot, Gemini CLI

Air Security disclosed Plugin4Shell (Sept 17): agents check out a marketplace-pinned plugin SHA but never verify HEAD, so a malicious branch named like the pin can swap in code on auto-update—zero-click RCE. Claude Code (≥2.1.179) and Codex (≥0.146.0) are patched; Copilot has no fix yet, and deprecated Gemini CLI will not be patched.

More news

View all

UN System Data Commons adds MCP so agents can query UN statistics

The UN launched System Data Commons (built on Google’s open source Data Commons) with MCP so agents can pull authoritative stats from 20 agencies at launch, with lineage back to the source. A UNICEF benchmark found six frontier models averaged just 21.2% accuracy on development indicators without that grounding…

TechCrunch

GitLab 19.4 expands MCP server with governed CI/CD and MR tools

GitLab 19.4 adds beta MCP tools so agents can run pipelines, open/update merge requests, triage vulnerabilities, and manage work items—with read only actions auto allowed and writes gated by the same tool governance as Duo. A new “merge request created” trigger can fire flows as soon as a diff is ready…

GitLab

Spotted something we missed? Start a thread.