← Back to live feed

Sunday, Sep 20, 2026

1
Plugin4Shell Zero Click RCE Hits GitHub Copilot and 3 Other AI AgentsMSFTPVT:ANTHPVT:OPAIGOOGL

A newly disclosed vulnerability allows attackers to inject malicious software into the plugin ecosystems of four leading AI coding agents. Known as Plugin4Shell, the flaw enables zero click remote code execution in Claude Code, Codex, GitHub Copilot, and Gemini CLI by exploiting a failure in SHA pinning. The agents check out a specific git commit but do not verify the identity of the code that lands on disk, allowing malicious auto-updates to run with full developer permissions.

Claude Code and Codex have released patches to fix the security gap, while GitHub Copilot remains unpatched. Google deprecated the Gemini CLI as an alternative to a fix. The flaw highlights security risks to the software supply chain as workers rely more heavily on AI agents and third-party tool ecosystems.

You're reading an older version of the story.
Plugin4Shell Zero Click RCE Bypassed SHA Pinning on 4 Leading AI Agents
7 tweets β€’ 6 sources
Earlier version from Sunday, Sep 20
Plugin4Shell Zero Click RCE Hits 4 AI Agents Including Copilot and Gemini CLI
5 tweets β€’ 4 sources
See all 7 tweets β†’