Finding / claude-code
2026-09-21-claude-code-plugin4shell-disclosed-in-window-fix-shipped-in-2-1-179-with-a-silent-changelog
AIR Security published Plugin4Shell on 2026-09-17. A marketplace plugin pinned to a 40-hex commit SHA could be swapped for other code, because git checkout prefers a ref over a commit of the same name and the agent did not verify the checkout resolved to the pinned commit. The attacker needs control of the plugin repository; AIR says GitHub rejects 40-hex branch names while Bitbucket and self-hosted git do not. AIR dates Anthropic’s fix confirmation to 2026-06-17 in 2.1.179. The 2.1.179 changelog entry at SHA 8187baaaafb3 lists nine items and none mentions SHA verification or plugin checkout.
Channel: tagged-release (2.1.179, before the window). Half: defect.
Operator consequence: Any Claude Code at 2.1.179 or later is not exposed to this variant, and stable 2.1.267 is well past it. The durable lesson is about the channel: an operator reading the changelog to decide upgrades could not have known this fix existed. Plugins sourced from Bitbucket or self-hosted git on older builds are the exposure to check.
Receipt
Finding metadata
Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0
Finding ID: 2026-09-21-claude-code-plugin4shell-disclosed-in-window-fix-shipped-in-2-1-179-with-a-silent-changelog
Accepted signals
Profile citations
- Claude Code / claim / plugin4shell-silent-fix
Source links
Primary links, including exact changelog lines when available.
- third party research2026-09-21-claude-code-plugin4shell-disclosed-in-window-fix-shipped-in-2-1-179-with-a-silent-changelogwww.air.security/blog-posts/plugin4shelltagged commit file2026-09-21-claude-code-plugin4shell-disclosed-in-window-fix-shipped-in-2-1-179-with-a-silent-changeloganthropics/claude-code / CHANGELOG.md