Signal

Plugin4Shell: a zero-click RCE bug hit Claude Code, Codex, Copilot and Gemini CLI at once — and two of the four are still unpatched

Security researchers disclosed Plugin4Shell on 17 September 2026, a plugin SHA-pinning bypass that let attackers silently swap in malicious code across four major AI coding agents — Claude Code, Codex, GitHub Copilot and Gemini CLI — without any action from the developer running them, exposing exactly how much trust teams have handed to agent plugin marketplaces.