---
format: "aidr-story-markdown/v1"
id: "62c3e330d01a3ddfb02a19eca4cbdbae2a208cc279bd281b24d998efc1f00264"
canonical_url: "https://aidr.today/62c3e330?lang=vi"
title: "Lỗ Hổng Zero Click Plugin4Shell Ảnh Hưởng Đến 4 AI Coding Agent, Bao Gồm Copilot"
lang: "vi"
requested_lang: "vi"
available_langs: ["en","vi"]
translation_fallback: null
fallback_fields: []
published_at: "2026-09-20T14:38:48.000Z"
category: "Legal"
topics: ["security","copilot","plugin4shell","vulnerability","coding-agents","coding","claude-code","codex"]
source_urls: ["https://marketbrief.now/cybersecurity/plugin4shell-zero-click-flaw-hits-4-ai-coding-agents-including-copilot-940e6deb","https://huggingnews.com/cybersecurity/plugin4shell-zero-click-flaw-hits-4-ai-coding-agents-including-copilot-940e6deb","https://x.com/theinformation/status/2101672773215039962","https://x.com/krushalkalkani/status/2101669015307288966","https://x.com/BulsTheRock/status/2101546201107866017","https://x.com/ankurinnovator/status/2101633912783229333","https://huggingnews.com/cybersecurity/plugin4shell-zero-click-rce-bypassed-sha-pinning-on-4-leading-ai-agents-68dcb247","https://marketbrief.now/cybersecurity/plugin4shell-zero-click-rce-bypassed-sha-pinning-on-4-leading-ai-agents-68dcb247"]
summary: "Lỗ hổng bảo mật nghiêm trọng Plugin4Shell đã được phát hiện trong 4 AI coding agent, bao gồm cả GitHub Copilot. Lỗ hổng này cho phép kẻ tấn công thực thi mã độc mà không cần bất kỳ tương tác nào từ người dùng, gây ra rủi ro lớn cho các nhà phát triển sử dụng các công cụ này."
---

# Lỗ Hổng Zero Click Plugin4Shell Ảnh Hưởng Đến 4 AI Coding Agent, Bao Gồm Copilot

> [Open the canonical story](<https://aidr.today/62c3e330?lang=vi>)

**Published:** 2026-09-20T14:38:48.000Z
**Category:** Legal
**Topics:** security, copilot, plugin4shell, vulnerability, coding\-agents, coding, claude\-code, codex

## Summary

Lỗ hổng bảo mật nghiêm trọng Plugin4Shell đã được phát hiện trong 4 AI coding agent, bao gồm cả GitHub Copilot\. Lỗ hổng này cho phép kẻ tấn công thực thi mã độc mà không cần bất kỳ tương tác nào từ người dùng, gây ra rủi ro lớn cho các nhà phát triển sử dụng các công cụ này\.

## Sources

- [Story source](<https://marketbrief.now/cybersecurity/plugin4shell-zero-click-flaw-hits-4-ai-coding-agents-including-copilot-940e6deb>)
- [Story source](<https://huggingnews.com/cybersecurity/plugin4shell-zero-click-flaw-hits-4-ai-coding-agents-including-copilot-940e6deb>)
- [Story source](<https://x.com/theinformation/status/2101672773215039962>)
- [Supporting source](<https://x.com/krushalkalkani/status/2101669015307288966>)
- [Supporting source](<https://x.com/BulsTheRock/status/2101546201107866017>)
- [Supporting source](<https://x.com/ankurinnovator/status/2101633912783229333>)
- [Story source](<https://huggingnews.com/cybersecurity/plugin4shell-zero-click-rce-bypassed-sha-pinning-on-4-leading-ai-agents-68dcb247>)
- [Story source](<https://marketbrief.now/cybersecurity/plugin4shell-zero-click-rce-bypassed-sha-pinning-on-4-leading-ai-agents-68dcb247>)

