important · Developer tools — Claude Code
A repository takeover could turn a Claude Code background plugin update into developer-context code execution.
Affects
Claude Code, Anthropic's cross-platform local coding agent and plugin host.
The demonstrated chain combines an installed plugin, repository control, a marketplace repin, a Git backend that permits a SHA-shaped branch, and background updates; the updater accepted that branch without checking that HEAD matched the pinned commit.
Detail and 4 sources
AIR reports a working demonstration and verification of the fix in Claude Code 2.1.179.
Sources
ResearchPlugin4Shell: SHA-Pinning Bypass Enables AI Coding Agent RCE – Lab SpaceResearchAIコーディングエージェント4製品に共通の脆弱性「Plugin4Shell」— プラグインのSHA固定を迂回し、無操作で悪性コードを実行させる手法をAIRが公表 | NEXSIGHT CYBER WIRECode / PoCRelease v2.1.179 · anthropics/claude-codeVendorPlugin4Shell - Zero Click RCE Vulnerability found in top 4 most popular coding agents, millions of agents affected