A zero-click RCE flaw in AI coding agents could have exposed enterprise systems

However, Claude Code, Codex, and GitHub Copilot can be tricked into running malicious code instead of the trusted plugin code associated with the SHA because they pass the SHA directly to Git to check out the plugin code but do not subsequently verify that Git has actually checked out the commit corresponding to that SHA, the researchers wrote.

That means an attacker who controls the plugin’s repository, either by publishing a benign plugin and later turning it malicious or by taking over the repository behind an existing trusted plugin, can exploit the gap by creating a new version of the repository containing malicious code and using the SHA of the legitimate commit as its name, the researchers explained.

As a result, when the agent asks Git to check out the SHA, Git resolve it to the attacker-controlled version, causing the agent to execute the malicious code even though it was instructed to use the reviewed commit, they said.

Donner Music, make your music with gear
Multi-Function Air Blower: Blowing, suction, extraction, and even inflation

Leave a reply

Please enter your comment!
Please enter your name here