Plugin4Shell: a zero-click RCE bug hit Claude Code, Codex, Copilot and Gemini CLI at once — and two of the four are still unpatched
Security researchers disclosed Plugin4Shell on 17 September 2026, a plugin SHA-pinning bypass that let attackers silently swap in malicious code across four major AI coding agents — Claude Code, Codex, GitHub Copilot and Gemini CLI — without any action from the developer running them, exposing exactly how much trust teams have handed to agent plugin marketplaces.
19 September 2026
Security researchers at AIR publicly disclosed a vulnerability called Plugin4Shell on 17 September 2026. The bug is a plugin SHA-pinning bypass: agents are meant to check out the exact commit a plugin marketplace pinned, as a safeguard against a plugin author quietly swapping in different code later. Plugin4Shell breaks that guarantee. An agent checks out the commit hash it was told to trust, but never actually verifies that the code living at that hash is still what it was when it was pinned. An attacker who controls the plugin’s upstream repository can rewrite history so the pinned hash resolves to malicious code while still looking honoured.
What makes it “zero-click” is the auto-update behaviour most of these agents ship with by default. Claude Code and Codex both automatically pull plugin updates without prompting the user, so the moment an attacker swaps the code behind a pinned commit, every installed copy of that plugin updates itself into a backdoor — no phishing link, no malicious command, no developer error required. The access an attacker gets matches whatever the agent itself can reach: source code, credentials in the environment, and often direct system access, since these agents typically run with the same permissions as the developer using them.
Patch status is the real story
Four agents shared the same underlying flaw, and the response split badly. Anthropic patched Claude Code in version 2.1.179. OpenAI patched Codex in version 0.146.0. Microsoft was notified of the identical issue in GitHub Copilot and, as of this signal, has not shipped a fix. Google’s response was to deprecate Gemini CLI entirely rather than patch it — which means every existing Gemini CLI install stays exposed indefinitely, since there’s no fixed version to upgrade to.
That gap matters more than the vulnerability itself. A shared flaw across four competing products shows the plugin-pinning assumption was an industry-wide blind spot, not one vendor’s mistake. But a two-speed patch response — fixed here, silently abandoned there — means the actual risk to any given team now depends entirely on which tool they standardised on and how quickly their vendor moved, not on how carefully their own developers behaved.
So what
If your team or your development partner uses AI coding agents with plugin marketplaces switched on, this is worth an immediate, concrete check rather than a general policy conversation: which agents are in use, are they on the patched versions (Claude Code 2.1.179+, Codex 0.146.0+), and is auto-update for plugins something you actually want enabled by default given this pattern. If Copilot or Gemini CLI are part of your stack, treat that as an open, unresolved risk until the vendor says otherwise. This is exactly the kind of operational detail that separates a team using AI coding tools carefully from one that’s just moving fast — see how we approach it on our AI-assisted development page, or get in touch if you want a second opinion on your team’s or vendor’s AI tooling exposure.