Common Security Flaw Found Across Major AI Coding Assistants from Leading Tech Firms

Deep News
1 hour ago

While much of the AI industry focuses on theoretical threats that large language models might pose to the internet or humanity, researchers are highlighting a more immediate concern: security vulnerabilities in AI coding agents from Anthropic, OpenAI, Google, and Microsoft that present real risks to businesses.

New research exclusively shared with The Information reveals that Claude Code, Codex, Gemini CLI, and GitHub Copilot recently had a software vulnerability, with most products now patched. If exploited, this flaw could allow attackers to hijack a user's coding agent without the victim's knowledge. The study, conducted by venture-backed cybersecurity startup Air, found that all four coding agents share the identical defect in how they process "skills" plugins, which are add-ons that guide an agent to read a set of instructions and files to complete a specific task.

Where to begin with this issue

According to Niv Hoffman, co-founder and CTO of Air, it is highly unusual for one security bug to affect four major AI coding agents simultaneously. He noted that four engineers across four different companies made the exact same logical error in their implementation of the validation mechanism. Other security startups have previously discovered multiple vulnerabilities in Microsoft's Copilot, confirming that AI carries risks of leaking confidential client information.

Skills plugins, which resemble downloadable browser extensions, are popular among advanced users who use them to enable AI agents to browse the web or write code according to specific logic. Many practitioners download these plugins from open-source repositories, with both Anthropic and Microsoft offering such add-ons. All four coding agent providers attempt to scan and block malicious code within plugins, but after a customer downloads and scans a plugin, the agent automatically installs software updates published by the plugin's author.

Air's blog details the "Plugin4Shell" vulnerability: if a hacker embeds malicious code into a plugin while keeping the original plugin name, the AI coding agent will automatically download the malicious update without detecting the change or warning the user. This means an attacker could upload a seemingly useful, harmless plugin to a public marketplace, wait for users to install it, then modify the plugin to inject malicious code that could steal intellectual property. Hoffman stated that Air found no evidence of active exploitation before reporting the vulnerability to vendors in June.

While Microsoft has not yet confirmed a fix for the GitHub Copilot vulnerability, the other three vendors have completed patches. A GitHub spokesperson did not directly address the Copilot issue but noted that attackers cannot host such malicious plugins on GitHub repositories, as the platform prohibits uploading different software with identical names. Spokespersons for Google, OpenAI, and Anthropic declined to comment.

Ken Huang, an adjunct professor at the University of San Francisco and AI security consultant, remarked that the research should prompt companies to control employee usage of plugins within coding agents. He suggested that while much of the AI safety hype over the next six to twelve months may be overblown, these real-world security issues in AI agents are underestimated. Given the widespread use of AI plugins by knowledge workers, this vulnerability demonstrates that even seemingly trustworthy plugins can be hijacked.

Why this matters for CIOs and developers

This is not just a theoretical concern. Air's findings underscore that the rapid adoption of AI coding tools in enterprise environments introduces supply-chain risks similar to those seen in traditional software. As companies increasingly rely on third-party plugins to extend the functionality of their coding agents, the attack surface expands. Organizations should implement strict policies for plugin usage, verify plugin authenticity, and apply updates only from trusted sources. The fact that all four major tool vendors were affected simultaneously highlights a systemic issue in the emerging AI development ecosystem that warrants close attention from security teams.

In related news, Salesforce CEO Marc Benioff pushed back against data leakage concerns raised by Palantir CEO Alex Karp, who suggested that model providers like Anthropic and OpenAI could essentially steal business data from enterprise clients. Speaking at the Dreamforce conference in San Francisco, Benioff argued that claims from other vendors about using a particular large model equating to handing over intellectual property are not accurate. He urged listeners to recognize that such rhetoric often comes from parties with vested interests seeking to steer customer decisions.

Benioff took the opportunity to highlight Salesforce's zero-data-retention policy, which states that while products are powered by model vendors like Anthropic, Salesforce does not share customer data with them. However, as previously reported, Anthropic has modified its zero-data-retention policy for its most advanced models. Customers remain concerned that sensitive company information could be exposed to vendors, and without contractual guarantees, Anthropic can alter its data retention rules at any time. The situation is more nuanced than Benioff's description suggests.

New contenders enter the orchestration layer

Just a few months ago, the "orchestration layer" was a niche term among engineers, used to describe software that helps AI agents choose the right tools and models to complete tasks cost-effectively. The concept has now gained mainstream attention, particularly among software companies seeking to position themselves as neutral intermediaries between enterprises and large model providers.

Salesforce dedicated significant time at Dreamforce to showcase its enterprise-oriented orchestration product, which can assign plugin permissions to customer AI agents, allowing them to perform actions within Salesforce accounts. Meanwhile, competitor HubSpot announced its own orchestration tool, named Aviator, at its customer conference in Boston this week, according to Chief Product and Technology Officer Duncan Lennox.

While HubSpot's promotional materials did not mention the product, Lennox indicated that Aviator is central to the company's AI strategy. The orchestration layer acts as a software middleware that selects suitable tools and models for HubSpot's AI agents, optimizing costs for CRM-related tasks such as generating ad copy and emails for marketing teams. Lennox noted that HubSpot has been developing this orchestration layer for three years; the system distributes tasks to various AI models, including those from OpenAI, based on task complexity.

Disclaimer: Investing carries risk. This is not financial advice. The above content should not be regarded as an offer, recommendation, or solicitation on acquiring or disposing of any financial products, any associated discussions, comments, or posts by author or other users should not be considered as such either. It is solely for general information purpose only, which does not consider your own investment objectives, financial situations or needs. TTM assumes no responsibility or warranty for the accuracy and completeness of the information, investors should do their own research and may seek professional advice before investing.

Most Discussed

  1. 1
     
     
     
     
  2. 2
     
     
     
     
  3. 3
     
     
     
     
  4. 4
     
     
     
     
  5. 5
     
     
     
     
  6. 6
     
     
     
     
  7. 7
     
     
     
     
  8. 8
     
     
     
     
  9. 9
     
     
     
     
  10. 10