Avalerion Intelligence Edition 016: Four coding agents, one flaw, two still unpatched

Avalerion Intelligence · Edition 016

Tuesday 22 September 2026 · AI, Data & Enterprise Transformation for the Nordics, UK & Ireland

Four coding agents, one flaw, two still unpatched

The One Thing. Last week the risk in AI moved from the model to everything bolted onto it. On 17 September researchers showed that the plugin systems of the four leading coding agents could be made to install an attacker's code while appearing to honour a pinned, trusted version. Two vendors have patched. One has not, and one is retiring the product instead. If your developers use agents with plugins, you are running software nobody in your change process approved.
MoveWhoWhy it matters to you
Plugin4Shell: zero click code execution through the plugin systems of four coding agentsAIR Security (17 September)Agent plugins are a software supply chain, and most firms do not govern them as one
Claude Code and Codex patched, GitHub Copilot without a fix, Gemini CLI to be retiredAnthropic, OpenAI, Microsoft, Google (18 September)Your exposure depends on which agent your developers chose
Astra for Law: a frontier model configured for one profession, with 26 partner pluginsOpenAI (17 September)Model vendors now compete with the software built on top of them
Nokia Data Suite on Microsoft Fabric, trusted network data "in minutes instead of weeks"Nokia and Microsoft (17 September)Agents arrive after data products, not before
US proposes an AI incident notification channel with ChinaUS Treasury (20 September)AI incidents are now a matter for heads of state
Novo Nordisk puts Anthropic's models into research and software developmentNovo Nordisk (16 September)A Nordic flagship chose governance first, then scale

1. Top AI News

A trusted plugin can be swapped for a malicious one.
What happened. On 17 September AIR Security disclosed Plugin4Shell, a zero click remote code execution flaw in Claude Code, OpenAI Codex, GitHub Copilot and Gemini CLI. Plugin marketplaces pin each plugin to an exact commit. An attacker who controls a plugin's repository creates a branch named after that commit hash; Git resolves the branch first, so the agent installs the attacker's code while the pin still looks honoured. Claude Code and Codex update plugins in the background by default. AIR says a test skill it published reached more than 26,000 agents. Anthropic fixed Claude Code in version 2.1.179 and OpenAI fixed Codex in 0.146.0. Microsoft has not shipped a fix for Copilot, and Google is deprecating Gemini CLI in favour of Antigravity rather than patching it.
Why it matters. The pin was the control everyone relied on, and it did not hold.
What to do. This week, confirm the version of every coding agent in use and list which plugins each one has installed.

Washington wants an AI hotline with Beijing.
What happened. On 20 September in New York, US Treasury Secretary Scott Bessent proposed a US China AI dialogue with a notification system for AI incidents that rise to national security level. Chip export controls are excluded. The idea goes to the Trump and Xi summit in Washington this week.
Why it matters. Incident reporting for AI is becoming a state level expectation, and supervisors tend to follow.
What to do. Check that your incident process has a category for AI failures, with an owner.

China mass produces memory without the banned machines.
What happened. On 20 September CXMT announced mass production on its fifth generation DRAM platform, claiming at least 50 percent more dies per wafer and a 24 gigabit LPDDR5X chip, made without extreme ultraviolet lithography.
Why it matters. Memory is the tightest input in AI servers. TrendForce expected server DRAM contract prices to rise 13 to 18 percent in the third quarter. New supply eases that slowly and first for phones.
What to do. Assume hosted AI unit costs stay firm through 2027 in your budget.

2. Enterprise AI Trend: the model vendor moves into your software

On 17 September OpenAI launched Astra for Law, GPT-6 Astra configured for legal work, with a search index of more than 230 million URLs of United States law and 26 partner plugins, including iManage, Clio and Relativity. Selected firms get it first through a trusted access programme in ChatGPT and Codex, with the API to follow. Harvey and the Stockholm founded Legora will build on it, which means they now build on a product that competes with them. Expect the same pattern in finance, tax and service. When you buy a specialist AI application, ask what it adds that its model supplier could not ship next quarter, and what happens to your data and workflows if it cannot answer.

3. Data & AI Readiness: agents arrive after data products

On 17 September Nokia and Microsoft extended their partnership to combine Nokia Data Suite, a set of ready made telecom data products, with Microsoft Fabric. The claim is that operators reach trusted network data "in minutes instead of weeks", and the first agent use cases, voice service assurance and coverage analysis, sit on top of that. The order is the lesson. Nokia did not start with the agent. It started with governed, reusable data products and let agents consume them, with on premises deployment kept for operators with regulatory limits. If your agent programme has no named data products underneath it, each new agent will rebuild its own data pipeline and inherit its own errors.

4. Business Process Spotlight: the update nobody approved

Plugin4Shell is a security story, but the gap it exposed is a process one. Most organisations run formal change control on production software and none on the plugins, skills and connectors their developers add to coding agents, which update themselves overnight. Astra for Law launched with 26 plugins on day one; plugin estates will only grow. Treat them like any other third party dependency. Keep an approved list, pin versions you have reviewed, turn off automatic plugin updates where the tool allows it, and route new plugins through the same approval path as a new library. The work is dull and it closes the door Plugin4Shell used.

5. Nordic Technology: Novo Nordisk chooses governance first

On 16 September Novo Nordisk, headquartered in Bagsværd, announced a collaboration with Anthropic. Novo will test the Claude Science workbench in specific research and development workflows and use Anthropic's models to strengthen software development across the company. Both sides stressed that the programme was "designed with robust data governance and human oversight." Named workflows, a stated governance design and a defined scope is the pattern that gets AI past the pilot stage in regulated industries. In Sweden, the 13 September election gave the opposition 176 seats to 173, and a new government will inherit the national AI strategy published in February.

Avalerion's Take. Your AI estate is now mostly things you did not build and did not approve. A year ago the question was which model to trust. Last week showed that the exposure sits in the layers around it: plugins that install themselves, vendor products that absorb the tools you bought, and data pipelines rebuilt for every new agent. None of this calls for slowing down. It calls for the ordinary disciplines of software and data management, applied to AI without exception: an inventory, an owner, a change process, governed data underneath. Novo Nordisk and Nokia both started there. The firms that skip it will spend next year finding out what their agents are running. Architecture before acceleration.

Do this next. Thirty minutes with us: which coding agents and plugins run in your estate, who approves a new one, and which data products your agents actually stand on. We will map all three with you. No pitch, no deck.

Book an AI Readiness Session

Recommended reading: What AI readiness actually means for Nordic companies and Why most enterprise AI projects still fail, at avalerions.com/insights

Frequently asked questions

What is Plugin4Shell?

Plugin4Shell is a zero click remote code execution flaw disclosed by AIR Security on 17 September 2026. It affects the plugin systems of Claude Code, OpenAI Codex, GitHub Copilot and Gemini CLI. An attacker who controls a plugin repository creates a branch named after the pinned commit hash, so the agent installs malicious code while the pin appears honoured. Claude Code 2.1.179 and Codex 0.146.0 contain fixes.

Which AI coding agents are still exposed to Plugin4Shell?

As of 18 September 2026, Microsoft had not shipped a fix for GitHub Copilot. Google chose to deprecate Gemini CLI rather than patch it and advises users to move to Antigravity. Anthropic patched Claude Code in version 2.1.179 and OpenAI patched Codex in version 0.146.0. Organisations should confirm installed versions and review installed plugins.

What is OpenAI Astra for Law?

Astra for Law, launched on 17 September 2026, is GPT-6 Astra configured for legal work. It includes a search index of more than 230 million URLs of United States law, legal analysis and writing instructions, controls for law firms and 26 partner plugins. Selected firms receive it first through a trusted access programme, with API access to follow. Harvey and Legora will build on it.

What did Novo Nordisk and Anthropic announce?

On 16 September 2026 Novo Nordisk announced a collaboration with Anthropic. Novo will test the Claude Science workbench in specific research and development workflows to support drug discovery, and use Anthropic's models to strengthen software development across the company. Both companies said the programme was designed with robust data governance and human oversight.


Sources

  • AIR Security, "Plugin4Shell: Zero Click RCE Vulnerability found in top 4 most popular coding agents", 17 September 2026: air.security
  • Help Net Security, "Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched", 18 September 2026: helpnetsecurity.com
  • SecurityOnline, "Plugin4Shell: Zero-Click RCE Hits Four AI Coding Agents": securityonline.info
  • Al Jazeera, "US proposes AI safety notification mechanism in talks with China", 20 September 2026: aljazeera.com
  • CNN Business, "Bessent proposes AI safety notifications in talks with China ahead of Xi-Trump meeting", 20 September 2026: cnn.com
  • TechNode, "CXMT announces mass production of fifth-generation DRAM platform", 21 September 2026: technode.com
  • TrendForce, "Server DRAM Contract Prices Expected to Rise 13-18% QoQ in 3Q26", 9 July 2026: trendforce.com
  • The Next Web, "OpenAI launches Astra for Law, and its own legal research index", 18 September 2026: thenextweb.com
  • Artificial Lawyer, "OpenAI Launches Astra For Law", 18 September 2026: artificiallawyer.com
  • Nokia, "Nokia accelerates network automation through agentic, unified data foundation with Microsoft", Espoo, 17 September 2026: globenewswire.com
  • Novo Nordisk, "Novo and Anthropic will collaborate to advance drug discovery with Claude", Bagsværd, 16 September 2026: globenewswire.com
  • Wikipedia, "2026 Swedish general election": en.wikipedia.org
  • Government Offices of Sweden, "Sweden's AI Strategy", February 2026: government.se