Vulnerabilities'Plugin4Shell' flaw hits major AI coding agents
Researchers at Air say a plugin pinning bypass gives attackers zero-click code execution on machines running Claude Code, Codex, Gemini CLI and Copilot.
17 Sept 2026
Security researchers at Air disclosed a zero-click remote code execution vulnerability, dubbed Plugin4Shell, affecting Claude Code, Codex, Gemini CLI, and Microsoft Copilot/GitHub Copilot. The flaw exploits a bypass of plugin SHA-pinning in trusted marketplaces, letting attackers swap pinned plugin commits for malicious code that auto-updates into agents, potentially giving full access to any asset the agent can reach.
Disclosed 17 September 2026 · Record updated 17 September 2026
Attackers could achieve zero-click remote code execution via compromised plugin marketplaces, gaining full access to any asset or data the AI coding agent can reach; nearly 90% of Fortune 500 companies use Copilot, one of the unpatched agents.
VulnerabilitiesResearchers at Air say a plugin pinning bypass gives attackers zero-click code execution on machines running Claude Code, Codex, Gemini CLI and Copilot.
17 Sept 2026