← Back to live feed

Sunday, Sep 20, 2026

1
Plugin4Shell Zero Click Flaw Hits 4 AI Coding Agents Including CopilotGOOGLPVT:ANTHPVT:OPAIMSFT

A remote code execution vulnerability allows attackers to target developer machines via compromised plugin updates for a group of leading AI coding assistants. This zero-click flaw, dubbed Plugin4Shell, impacts Gemini CLI, Claude Code, Codex, and Copilot by allowing unverified auto-updates to run with full system permissions.

The exploit requires the actor to maintain control of the plugin repository to insert malicious code into skills already installed by the user. By breaking SHA-pinning, the hole ensures locked plugin commits are never verified, which threatens security as workers rely more heavily on AI coding agents and third-party tools.

You're reading an older version of the story.
Plugin4Shell Zero Click RCE Bypassed SHA Pinning on 4 Leading AI Agents
7 tweets β€’ 6 sources
Earlier version from Saturday, Sep 19
Plugin4Shell Flaw Lets Attackers Slip Malicious Code Into 4 Leading AI Coding Agents
2 tweets β€’ 2 sources
See all 4 tweets β†’