Plugin4Shell breaks the one guarantee AI coding agent plugins were supposed to give you
Security researchers disclosed Plugin4Shell on 17 September 2026 — a zero-click vulnerability that lets a malicious plugin repository silently swap in unreviewed code across Claude Code, Codex, GitHub Copilot and Gemini CLI, breaking the SHA-pinning mechanism each tool relies on to keep installed plugins locked to a reviewed version.
22 September 2026
Air Security disclosed Plugin4Shell on 17 September 2026 — a zero-click vulnerability affecting the plugin marketplaces of four of the most widely used AI coding agents: Anthropic’s Claude Code, OpenAI’s Codex, Microsoft’s GitHub Copilot and Google’s Gemini CLI. The bug was found in May 2026 and reported to each vendor the following month, giving all four several months’ notice before public disclosure. Two have patched it. Two haven’t.
What actually breaks
Every one of these agents lets you install third-party plugins from a marketplace, then “pin” the installed version to a specific, reviewed commit — the same trust model package managers have used for years to stop a plugin silently changing under you. Plugin4Shell defeats that model entirely: if an attacker controls the plugin’s source repository, they can change what the pinned reference actually points to, so an agent that believes it’s checking out the exact commit a developer reviewed instead pulls down malicious code, with no prompt, no warning, and no action required from the victim beyond having installed the plugin in the first place. Researchers are calling it the first genuine supply-chain vulnerability of the AI agent ecosystem, and the “zero-click” label is doing real work here — this isn’t a phishing link or a social-engineering step, it’s a silent failure in a security mechanism developers were told to rely on.
Patch status is the part worth tracking
Anthropic shipped a fix in Claude Code 2.1.179. OpenAI patched Codex in version 0.146.0. Microsoft was notified on the same timeline but hadn’t shipped a fix for GitHub Copilot as of disclosure, and Google declined to patch Gemini CLI, treating it as a deprecated consumer tool. If your team — or an outsourced dev partner — is running Copilot or Gemini CLI with third-party plugins installed, that’s a live, unpatched exposure today, not a historical footnote.
So what
This is the fourth or fifth disclosure this year of a structural flaw in how AI coding agents handle trust boundaries, and the pattern is consistent: the vulnerability isn’t in the model, it’s in the scaffolding built around it — plugin marketplaces, default permissions, shared checkouts. If you’re commissioning software from a team that leans on AI coding agents and plugin ecosystems to move fast, it’s a reasonable question to ask directly: which agents and plugins are in use, are they on the patched versions, and is there a process for tracking disclosures like this one as they land — because at the current rate, this won’t be the last one this year. That’s the kind of engineering discipline we build into AI-assisted development work as standard, not as a response to a headline. Get in touch if you want your current stack checked against it.