September 20, 2026
4223909-0-19339900-1789746167-Github-claude-codex-AI.jpg

I show You how To Make Huge Profits In A Short Time With Cryptos!

Nevertheless, Claude Code, Codex, and GitHub Copilot might be tricked into operating malicious code as a substitute of the trusted plugin code related to the SHA as a result of they cross the SHA on to Git to take a look at the plugin code however don’t subsequently confirm that Git has truly checked out the commit akin to that SHA, the researchers wrote.

Which means an attacker who controls the plugin’s repository, both by publishing a benign plugin and later turning it malicious or by taking up the repository behind an current trusted plugin, can exploit the hole by creating a brand new model of the repository containing malicious code and utilizing the SHA of the professional commit as its identify, the researchers defined.

Because of this, when the agent asks Git to take a look at the SHA, Git resolve it to the attacker-controlled model, inflicting the agent to execute the malicious code although it was instructed to make use of the reviewed commit, they stated.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *