Saturday, 19 September 2026
0 agent hacks today 8 vs yesterday (8)

Zero-click 'Plugin4Shell' RCE flaw found in major AI coding agents

Security researchers at Air disclosed a zero-click remote code execution vulnerability, dubbed Plugin4Shell, affecting Claude Code, Codex, Gemini CLI, and Microsoft Copilot/GitHub Copilot. The flaw exploits a bypass of plugin SHA-pinning in trusted marketplaces, letting attackers swap pinned plugin commits for malicious code that auto-updates into agents, potentially giving full access to any asset the agent can reach.

Disclosed 17 September 2026 · Record updated 17 September 2026

Impact

Attackers could achieve zero-click remote code execution via compromised plugin marketplaces, gaining full access to any asset or data the AI coding agent can reach; nearly 90% of Fortune 500 companies use Copilot, one of the unpatched agents.

Our coverage

Sources

  1. theregister.comhttps://theregister.com/security/2026/09/17/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom/5297335