← Back to live feed

Sunday, Sep 20, 2026

1
Plugin4Shell Zero Click RCE Hits 4 AI Agents Including Copilot and Gemini CLIPVT:ANTHPVT:OPAIMSFTGOOGL

Claude Code, Codex, Copilot, and Gemini CLI contained a zero click remote code execution flaw that bypassed security verification for third party plugins. The vulnerability, named Plugin4Shell, allowed attackers to replace a pinned plugin commit with malicious code that executed with full developer permissions on a user's machine by breaking SHA pinning.

Claude Code and Codex released patches for the vulnerability, which requires an attacker to have control of the plugin repository to succeed. The flaw exposes security risks in the AI agent supply chain by allowing malicious code to be injected into tools after users have already downloaded the software.

You're reading an older version of the story.
Plugin4Shell Zero Click RCE Bypassed SHA Pinning on 4 Leading AI Agents
7 tweets β€’ 6 sources
Earlier version from Sunday, Sep 20
Plugin4Shell Zero Click Flaw Hits 4 AI Coding Agents Including Copilot
4 tweets β€’ 3 sources
See all 5 tweets β†’