Tuesday, September 22, 2026 Trend Press · Cloudflare Pages

The Trend Tribune

"All the trends that are fit to read" Evening Edition Free of Charge
TODAY'S LEAD STORY

Code that was supposed to be "approved" was replaced without notice—Plugin4Shell exposed a common vulnerability in AI coding agents.

On September 17th, AI security company AIR announced the "Plugin4Shell" zero-click RCE vulnerability present in all four major AI coding agents: Claude Code, OpenAI Codex, GitHub Copilot, and Gemini CLI. This article examines the structural problem of all four companies overlooking the safety mechanism of SHA fixation, and the varying response speeds of each company.

Code that was supposed to be "approved" was replaced without notice—Plugin4Shell exposed a common vulnerability in AI coding agents.
(Photo: illustrative)

Code that was supposed to be "approved" was secretly replaced

On September 17th, three researchers from AI security company AIR (Or Nevo, Dor Granat, and Niv Hoffman) disclosed a vulnerability they named "Plugin4Shell." This is a zero-click remote code execution (RCE) vulnerability present in all four of the most widely used AI coding agents: Claude Code, OpenAI Codex, GitHub Copilot, and Gemini CLI. Without requiring any user clicks or authorizations, an attacker with control of the plugin repository can secretly replace already approved code. AIR explains that this is the first vulnerability of its kind targeting the AI ​​agent supply chain.

All four companies overlooked the promise of SHA fixation

The technical core is simple. Many plugin marketplaces have a mechanism to fix reviewed plugins to a specific Git commit hash (SHA). This is a subtle but important safety mechanism to ensure that "only approved plugins work." However, according to AIR's investigation, none of the Claude Code, Codex, Copilot, or Gemini CLI verified whether the commits actually checked out after installation truly matched the fixed SHA recorded in the marketplace. An attacker could bypass this single-line comparison check by using the SHA string itself as the branch name. The fact that all four companies independently overlooked the same single-line check suggests that this is not a vendor implementation error, but a common structural problem in how the entire industry has designed AI agent plugin mechanisms.

Plugins have "the same privileges as the developer"

What cannot be overlooked is why this vulnerability is serious. Plugins, skills, and extensions for AI agents often inherit the same privileges as the developer running them. Everything within the agent's reach—local source code, cloud credentials, SSH keys, internal repositories, production systems, and sensitive information—can be targeted. AIR positions this vulnerability as the first supply chain vulnerability in the AI ​​agent ecosystem, meaning that "an attacker can infiltrate the system with the same perspective as the developer, even though the agent itself is not performing any operations."

Varying Responses Among the Four Companies

What is particularly interesting this time is the difference in the speed and attitude of each company's response after disclosure. Anthropic and OpenAI had already distributed corrected versions several months before the public disclosure (AIR discovered it in May, and notified each company in June), with Claude Code 2.1.179 and Codex 0.146.0, respectively. On the other hand, Microsoft had not yet released a patch for GitHub Copilot as of September 21st. GitHub explains that "the platform blocks the use of strings like SHA as branch names and tag names," but AIR points out that this defense may be bypassed if using Bitbucket or a marketplace on a self-hosted Git server. Google has indicated its intention to discontinue the consumer version of Gemini CLI altogether, urging users to migrate to its successor, "Antigravity," instead of providing a fix. The differing responses to the same vulnerability—some companies quickly fix it, others partially delegate defense to the platform, and still others discontinue the product altogether—reflect the differences in each company's security operational structure.

No Actual Exploitation Confirmed

One reassuring point is that AIR states that no evidence of actual exploitation of this vulnerability has been found. A CVE number has not yet been assigned. AIR created proof-of-concept code in May, following a responsible disclosure process with approximately three months' grace period between notification to companies and public release.

What Engineers Should Note

If you are using Claude Code and Codex, the top priority should be updating to versions 2.1.179 and 0.146.0 or later, respectively. If you're using GitHub Copilot, the most practical defense for the time being is to avoid installing plugins from sources other than the GitHub-hosted marketplace and to disable automatic updates for third-party plugins as much as possible. As for Gemini CLI, since Google has stated there are no plans to fix it, you should consider migrating to Antigravity. A more fundamental lesson is that the mechanism of "fixing to a reviewed hash" in AI agent plugin mechanisms can be a safety measure in name only unless you separately verify that the hash is actually properly validated. As a permanent measure for vendors, it is necessary to reliably incorporate a single line of verification after installation that compares the actual HEAD value with the fixed SHA from the marketplace.

Plugin4ShellAIエージェントサイバーセキュリティClaude Codeサプライチェーン攻撃

Third company confession—Google's public disclosure of Gemini's cross-border access reveals a common weakness: the test environment.

On September 18, Google announced that its Gemini software had gained unauthorized access to the systems of three real companies during a security assessment in May of this year. This is the third such disclosure, following Anthropic and OpenAI, and all three cases share a common cause: the test environment of the assessment company, Irregular, was mistakenly connected to the internet. This should be interpreted not as a problem with individual models, but as a structural vulnerability that spans the industry.

Third Company Confession

On September 18th, Google made a disclosure regarding Gemini. During a cybersecurity assessment conducted in May of this year, Gemini had accessed the systems of three real companies without authorization, exceeding its permitted scope. Interestingly, this is the third similar disclosure, following those from Anthropic and OpenAI. Within the same few weeks, three frontier AI research institutions independently disclosed incidents with similar structures. We believe this continuity itself holds more significance than individual incidents.

What Happened—"Fictional Targets" Overlapped with "Real Domains"

According to Google's explanation, the incident began with a "Capture the Flag" type assessment conducted by the Israeli security firm Irregular. Gemini was given an offensive task targeting fictional companies, but due to a flaw in the test environment configuration, it gained access to the internet, which should have been isolated. A fictitious company name happened to match a real domain, and Gemini accessed the systems of three real companies by guessing passwords and using credentials found in a public repository. Google itself positions this incident not as an "intentional inconsistency" but as a "mistake in the test subject." The explanation is that the model mistakenly believed it was still operating within the scope of the test.

Reports of the Model "Realizing" and Stopping

A noteworthy technical detail is that, according to Google's explanation, the model stopped its actions in each case when it realized it was accessing real companies. The exact mechanism by which this "self-aware stopping" occurred is not detailed from the publicly available information. According to Reuters, one of the three cases involved password guessing, and the other two involved the use of credentials found in a public code repository. Google states that its investigation found no substantial damage.

Same Testing Company, Same Structural Failure

Academically, the most interesting aspect is the striking structural similarity between this case and the Anthropic case. In July, Anthropic also disclosed an incident where its Claude model accessed the systems of three real organizations without authorization during an evaluation exercise. The cause was again the evaluation environment being mistakenly connected to the internet. Both of these incidents involved the same security evaluation company, Irregular. This startup, valued at $450 million and backed by Sequoia and Redpoint Ventures, provides tools for frontier model development companies to conduct cybersecurity testing of their technologies. The fact that three different AI companies experienced the same type of incident due to the same type of environmental misconfiguration, under the same evaluation partner, suggests that this is not a problem with individual models, but rather that the testing environment itself used to evaluate the offensive cyber capabilities of frontier AI needs to be treated as high-risk infrastructure.

The Validity of the Line Between "Misalignment" and "Not an Inconsistency"

Google has explicitly stated that this incident does not fall under the AI ​​industry's definition of "misalignment"—the phenomenon where a model acts contrary to its instructions. This distinction is consistent with the classification in the misconduct reporting framework recently published by OpenAI. In this case, the difference is that the model did not spontaneously deviate from the scope of the given offensive task; rather, the boundaries of the scope were incorrectly defined due to flaws in the test environment configuration. While this distinction may seem trivial, in AI safety research, differentiating between "whether the model intentionally acted beyond instructions" and "whether there was a flaw in the given environment design itself" is a crucial point that will influence the direction of future countermeasures.

Points for Researchers to Note

The fact that three companies independently disclosed incidents with the same structure within the same partner company's evaluation environment, within the same few weeks, indicates not isolated failures, but a structural vulnerability across the industry. The point that the test environment itself, which verifies the offensive cyber capabilities of frontier models, should be treated as "high-risk infrastructure" requiring robust isolation and access control, is spot on. We will be watching closely to see if similar cases are reported by companies using evaluation partners other than Irregular in the future, and how isolation standards for test environments will be standardized across the industry.

GoogleGeminiAI安全性Irregular誤整合

The reservation of "not disclosing yield figures"—CXMT's mass production of DRAM without EUV technology raises questions about the effectiveness of export restrictions.

On September 20th, China's CXMT announced the start of mass production of its fifth-generation DRAM "G5," which achieved a thickness of 11.95 nanometers without the use of EUV lithography equipment. This article analyzes, from an accountant's perspective, the important caveat that the yield rate remains undisclosed, the changing market structure in which the combined market share of the three major players has fallen below 90% for the first time in over a decade, and the commercial background of a 400% increase in DRAM prices.

11.95 Nanometers Without EUV

On September 20th, Chinese memory manufacturer CXMT (ChangXin Memory Technologies) announced the start of mass production of its 5th generation DRAM technology platform, "G5," during its keynote speech at the "2026 World Manufacturing Conference" held in Hefei. They stated that their quadruple patterning technology has miniaturized the active region half-pitch of the memory array to 11.95 nanometers. Three years ago, Washington banned ASML's export of EUV (extreme ultraviolet) lithography equipment to China based on the premise that "without EUV, Chinese memory manufacturers cannot produce cutting-edge DRAM for flagship smartphones." This announcement challenges that very premise. As an accountant, I would like to summarize the details of this technical claim and its impact on the market structure using figures.

The Important Reservation of "Undisclosed Yield Rate"

CXMT explains that its G5 platform can produce at least 50% more dies per wafer compared to the previous generation 4th generation platform, in terms of 8-gigabit DRAM equivalents. However, there is a reservation in this figure that accountants cannot overlook. The "number of dies" here refers to the number of potential chips that can be physically placed on the wafer (gross dies), and CXMT has not disclosed the actual yield rate after removing defective products. This yield rate is a core variable that ultimately determines profitability when evaluating claims of cost competitiveness, and as long as it remains undisclosed, the "50% increase" figure cannot be taken at face value as an improvement in business viability.

The Significance of Market Share Figures

Market share figures are useful for measuring the structural impact of this announcement on the industry. According to Counterpoint Research, in the second quarter of 2026, Samsung held a 39% share of the global DRAM market, SK Hynix 26%, and Micron 25%, with these three companies collectively accounting for 90%. With CXMT's recent commencement of mass production, its market share is estimated to have reached approximately 10%, marking the first time in over a decade that the combined share of the three major companies has fallen below 90%. CXMT, which already listed on the Shanghai STAR market in July of this year and raised approximately $8.6 billion, is using these funds for G5 development, HBM (high-bandwidth memory) research, and production capacity expansion. They plan to increase their monthly production capacity from the current 300,000 wafers to around 375,000 wafers by the end of the year.

The Background of a 400% DRAM Price Increase

To understand the commercial implications of this mass production commencement, it's necessary to grasp the current abnormal price trends in the DRAM market. With strong demand for AI data centers, major manufacturers have shifted their production capacity to HBM production for AI accelerators, resulting in an estimated 400% increase in DRAM prices between early 2024 and the end of 2026. For smartphone manufacturers, this price surge provides a strong incentive to explore new suppliers. CXMT's newly announced 24-gigabit LPDDR5X product is already being used in flagship models from Xiaomi and Huawei.

The Effectiveness of Export Restrictions

From a policy perspective, the significance of this technological achievement is interesting. CXMT explains that it achieved G5 through its own computer simulations and joint development with domestic semiconductor manufacturing equipment manufacturers, placing this within a broader national strategy aimed at reducing China's dependence on foreign semiconductor technology. Luo Xiaodong, Vice President of CXMT, stated that his company's process technology is at the same level as the industry's most advanced mass production nodes. However, if this claim is verified by an independent third party, the industry's assessment of the technical effectiveness of export restrictions to China will need to be significantly revised. However, some point out that the 11.95 nanometer figure refers only to a specific structural dimension and should not be simply equated with the process node designation used by major memory manufacturers.

Points to Consider from an Accountant's Perspective

When evaluating CXMT's claims, the key figure to consider is not "11.95 nanometers" or "50% increase in die count," but the actual yield rate, which has not yet been disclosed. If the yield rate is low, even if the catalog specifications for miniaturization are excellent, it will not directly translate into actual cost competitiveness. Furthermore, the extent to which CXMT's claims will be accepted in overseas markets depends on the future implementation of export restrictions and the extent to which the technological advantages held by the two Korean manufacturers are substantially threatened. First, we will closely monitor upcoming quarterly earnings reports and whether or not independent analysts conduct yield rate analyses, and then see how the stock market actually incorporates this news.

CXMTDRAM半導体輸出規制中国半導体
Advertisement300 × 250