Friday, Sep 18, 2026
1 Plugin4Shell Zero Click RCE Hits 4 AI Agents Including GitHub CopilotPVT:ANTHPVT:OPAIMSFTGOOGL π Cybersecurity Sep 18, 7:06 AM EDT 3/3
Anthropic, OpenAI, Microsoft, and Google are managing a high-severity security flaw that allows attackers to run unauthorized code through malicious plugin updates. The vulnerability, known as Plugin4Shell, enables zero-click remote code execution by bypassing SHA-pinning on the auto-update path of 4 AI coding agents. Users of Claude Code, OpenAI Codex, GitHub Copilot, and Gemini CLI can have their systems compromised if an attacker controls the underlying plugin repository.
The exploit provides access to local source code, SSH keys, and cloud credentials because plugins inherit the permissions of the agent's developer. Claude Code version 2.1.179 and Codex version 0.146.0 contain fixes for the flaw. GitHub Copilot remains vulnerable, while Google has deprecated the Gemini CLI in favor of Antigravity without providing a patch for the original tool.