Plugin4Shell: Zero-Click RCE in AI Coding Agents
Plugin4Shell is a zero-click RCE in Claude Code, Codex, Copilot and Gemini CLI that swaps pinned plugin code. What it is, who's patched, and how to respond.
Researchers at AIR Security, a startup focused on defending enterprise AI agents, have disclosed a zero-click remote code execution flaw affecting the four most widely used AI coding agents: Anthropic’s Claude Code, OpenAI’s Codex, GitHub Copilot and Google’s Gemini CLI. Dubbed Plugin4Shell, the researchers describe it as the first supply-chain vulnerability native to the AI-agent ecosystem — and, by their count, one that potentially exposes millions of installed agents.
The details, published this week, matter well beyond the four named products. They describe a category of attack — silently swapping the code behind a plugin a developer believes they have locked down — that any agent relying on the same trust mechanism could inherit.
What Plugin4Shell does
Modern coding agents are extensible through plugins, and security-conscious developers pin those plugins to a specific, reviewed version using a 40-character Git commit hash (SHA). The pin is the safety guarantee: it is supposed to lock the installed code to exactly the commit that was audited, so that a later change to the upstream repository cannot silently alter what runs on a developer’s machine.
Plugin4Shell breaks that guarantee. According to AIR Security, an attacker who controls the plugin’s repository can create a Git branch whose name is identical to the pinned 40-character commit hash. During checkout, Git may resolve the matching reference name ahead of the commit object of the same value — so the agent pulls the attacker’s branch while reporting a successful installation of the expected SHA. The developer sees the pin they trust; the machine runs code they never reviewed.
Because the swap requires no click, no approval and no reinstall from the victim, the attack is zero-click. The agent does the compromising on its own, on its next fetch.
Why the impact is severe
The reason this rises above a typical dependency bug is what plugins can touch. Coding-agent plugins generally run with the same permissions as the developer operating the agent — which, in practice, means access to:
- local source code and uncommitted work,
- cloud credentials and API keys,
- SSH keys,
- internal and private repositories,
- and, in many setups, production systems and secrets.
That is why The Register summarized the flaw as one that could “hand attackers the keys to the kingdom.” An agent compromised this way is not just running rogue code in a sandbox — it is running with the trust an organization has already extended to its developers. It is the same reason AI agent sandboxing has become a first-order concern: the blast radius of an agent is the blast radius of the human it acts for.
There is a second multiplier unique to coding agents. Unlike a conventional library that is imported once and executes in a narrow context, an agent runs continuously, reads across a developer’s whole working tree, and often has network egress to reach package registries and internal services. A plugin that quietly swaps in malicious code therefore does not just execute — it can observe. It can watch commands, harvest tokens as they are used, and exfiltrate on a schedule that blends into an agent’s normal, chatty traffic. For an attacker, a single silently poisoned plugin can become a durable foothold inside a development pipeline rather than a one-shot payload.
Plugin4Shell also sidesteps the very control developers reach for to prevent this. Pinning by hash is the software-integrity analog of subresource integrity (SRI) on the web — trust a specific, verified artifact, not a moving reference. When the pin itself can be subverted, the defense of choice becomes the vector.
The disclosure timeline
AIR Security says it built working proof-of-concept exploits against all four agents in May 2026 and privately notified the affected vendors the following month, before going public this week. As of the disclosure, no CVE identifier had been assigned and none of the four vendors had published a formal security advisory — so there is not yet an official CVSS severity score attached to the flaw, though the researchers characterize it as high-severity.
That coordinated-disclosure window produced an uneven response across the four vendors.
Who has patched — and who hasn’t
- Anthropic — patched. Claude Code addressed the issue in version 2.1.179. Users should confirm they are running that release or later.
- OpenAI — patched. Codex closed the hole in version 0.146.0. OpenAI also paid AIR Security a $6,500 bug bounty for the report.
- GitHub Copilot (Microsoft) — unpatched at disclosure. Microsoft had not shipped a fix when the research went public.
- Google Gemini CLI — will not be patched. Google has deprecated the Gemini CLI rather than remediate it, advising users to migrate off the tool.
That leaves two of the four major agents exposed as of publication — one awaiting a fix, one with no fix coming.
How to respond now
If your team uses any of these agents, treat this as an urgent hygiene item rather than a theoretical risk:
- Update immediately where a fix exists — Claude Code 2.1.179+ and Codex 0.146.0+.
- For unpatched or deprecated tools, restrict or disable third-party plugins until a fix ships, and follow Google’s guidance to migrate away from the Gemini CLI.
- Audit installed plugins and their source repositories, prioritizing any that run with access to credentials, SSH keys or production systems.
- Rotate secrets that a compromised agent could have reached if you cannot rule out exposure.
- Constrain agent permissions so a swapped plugin inherits the least privilege possible — the sandboxing and isolation practices in our AI agent sandboxing primer apply directly here.
The broader lesson is one the software world already learned the hard way in conventional package ecosystems: as we noted in our software supply chain security primer, integrity mechanisms are only as strong as the assumptions underneath them.
What it means
Plugin4Shell is a preview of a threat surface the industry has been building quietly all year. AI coding agents have moved from novelty to daily tooling, and with plugins they have grown a dependency ecosystem — one that inherits every hazard of traditional software supply chains, plus the agents’ unusually broad, credential-laden permissions.
Why it’s a turning point: the attack targets the integrity guarantee itself, not a careless configuration. Developers who did everything right — pinning to a reviewed commit — are precisely the ones exposed. That inverts the usual advice and makes the flaw as much about the trust model of agent plugins as about any single vendor’s bug. Adversarial manipulation of what an agent runs sits next to the prompt-injection and jailbreaking risks already dogging these tools; together they define the security frontier for autonomous developer tooling.
Who’s exposed and who’s covered: organizations on patched Claude Code and Codex builds are protected today; teams still running GitHub Copilot with third-party plugins, or the deprecated Gemini CLI, are not, and the fix timeline for them ranges from “pending” to “never.” The split response is its own signal — vendors do not yet agree on how seriously to treat agent-plugin integrity.
What to watch next: first, whether a CVE and formal advisories are issued, which would standardize severity and force the laggards’ hand. Second, Microsoft’s Copilot fix — the largest installed base still without a patch. And third, whether the agent vendors redesign plugin verification so a branch name can never shadow a pinned commit again. Until the trust model is fixed rather than the individual bug, expect Plugin4Shell to be the first of several. The safest posture, as ever with fast-moving agent tooling, is to grant these tools the least access they need and to verify what they actually run — not what they report running.
Keep reading
Kurumi · · 6 min read AI Stocks Fall, Cybersecurity Rallies on Slowdown Calls
Chip and AI names sold off while CrowdStrike and Palo Alto surged after Amodei, Altman and Musk backed pacing frontier AI. Jensen Huang pushed back.
Chisato · · 5 min read Palo Alto Networks Buys Console for $500M for AI SecOps
Palo Alto Networks is paying about $500M for AI startup Console to add agentic automation to its Cortex platform. Deal terms, strategy, and what it means.
Chisato · · 6 min read LiteLLM CVE-2026-59822: CISA KEV AI Infra Attacks
CISA added seven exploited flaws to its KEV catalog on Sept. 2, and three target AI infrastructure — LiteLLM, Kestra, and Starlette. What to patch and why it matters.