Cybersecurity
Plugin4Shell – Zero Click RCE Vulnerability found in top four coding agents
A zero-click Remote Code Execution (RCE) vulnerability, tracked as CVE-2023-4863, has been discovered in the Plugin4Shell library, which is used by four top coding agents, including Visual Studio Code, IntelliJ, Sublime Text, and Atom. The vulnerability allows an attacker to execute arbitrary code on a victim's system by manipulating the plugin's file path. The issue has been assigned a CVSS score of 9.8, indicating a critical severity level. The Plugin4Shell library is used by millions of developers worldwide, and the vulnerability has been fixed in version 1.15.0.
Read the full article at air.security →