← Back to live feed

Saturday, Sep 19, 2026

1
Plugin4Shell Zero Click RCE Hits 4 AI Agents in First AI Supply Chain FlawPVT:ANTHPVT:OPAIMSFTGOOGL
topics πŸ”’ CybersecurityπŸ€– AIπŸ’» Tech tags AIAI RegulationAI LegalAI ProductsAI AgentsTechCybersecurity PVT:ANTHPVT:OPAIMSFTGOOGL keywords GoogleSecurity

Anthropic's Claude Code, OpenAI's Codex, GitHub Copilot, and Google's Gemini CLI share a high-severity security flaw allowing remote code execution. The Plugin4Shell vulnerability targets the software supply chain by bypassing SHA pinning during auto-updates, enabling attackers with repository control to silently install malicious code. These add-ons inherit the developer's permissions, granting access to local source code, SSH keys, and cloud credentials.

Anthropic and OpenAI patched the vulnerability in Claude Code version 2.1.179 and Codex version 0.146.0 following disclosure by Air Security. GitHub Copilot remains unpatched, and the Google Gemini CLI is unpatched and deprecated. The flaw cannot be mitigated by the plugin marketplaces themselves, requiring users to update their agent software to prevent zero click attacks.

You're reading an older version of the story.
Plugin4Shell Zero Click RCE Bypassed SHA Pinning on 4 Leading AI Agents
7 tweets β€’ 6 sources
Earlier version from Friday, Sep 18
Plugin4Shell RCE Hits 4 AI Agents in First AI Supply Chain Vulnerability
4 tweets β€’ 4 sources
See all 5 tweets β†’