Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched – Help Net Security

Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched – Help Net Security
AIR uncovered Plugin4Shell, a zero-click RCE affecting Claude Code, Codex, GitHub Copilot, and Gemini CLI through a shared plugin SHA-pinning bypass. The flaw lets attackers swap in malicious code during background updates, with vendor responses ranging from patches to deprecation and no fix yet for GitHub Copilot. #Plugin4Shell #ClaudeCode #Codex #GitHubCopilot #GeminiCLI #AIR #Anthropic #OpenAI #Microsoft #Google #Antigravity

Keypoints

  • Plugin4Shell is a zero-click RCE affecting four major AI coding agents.
  • The bug breaks SHA pinning and enables plugin code swapping without user action.
  • Background auto-updates can reintroduce the malicious code after installation.
  • Attackers can abuse a trusted plugin or hijack an existing repository.
  • Anthropic and OpenAI patched their agents, while Microsoft has not and Google deprecated Gemini CLI.

Read More: https://www.helpnetsecurity.com/2026/09/18/plugin4shell-ai-coding-agents-vulnerability/