What the bug does

Security researchers at AIR Security disclosed a vulnerability on Thursday that they call Plugin4Shell, affecting the plugin systems of the four most widely used AI coding agents: Claude Code, OpenAI’s Codex, GitHub Copilot and Gemini CLI.

The flaw defeats SHA pinning. Pinning is the mechanism a plugin marketplace uses to lock an installed plugin to one specific, reviewed commit: the agent is supposed to fetch exactly the code that was approved, and nothing else. According to AIR, the agents check out the pinned commit but never verify that the local checkout actually resolved to it. The attack turns on git preferring a branch name over a commit hash when the two are identical.

AIR describes two routes in. An attacker can publish a benign plugin, wait for it to pass review and get pinned, then swap the content afterwards. Or an attacker can take over a legitimate plugin author’s repository through stolen credentials or tokens and push malicious code that passes the same check.

Close-up of a padlock on a metal door
Illustration: SHA pinning is meant to lock a plugin to one reviewed commit. Zechen Li · pexels · Pexels License

Why it counts as zero-click

Neither route needs the victim to install anything. Claude Code and Codex update installed plugins in the background by default, so code an attacker substitutes after approval reaches every machine with that plugin already installed, with no user action at all.

The consequence is remote code execution on a developer’s machine — the machine that typically holds source code, cloud credentials and production access.

Patch status

Anthropic fixed Claude Code in version 2.1.179. OpenAI fixed Codex in version 0.146.0. Microsoft has not shipped a fix for GitHub Copilot. Google has deprecated Gemini CLI and says it will not patch it.

That leaves two of the four still exposed. AIR is explicit that users cannot fix this from their side: “The pin is resolved inside the agent, so only an agent-side fix restores the guarantee.” A developer who pins a plugin to a reviewed commit gets no protection from an unpatched agent, because the agent is the component that fails to check.

A team working at laptops in an open-plan office
Illustration: Claude Code and Codex update installed plugins in the background by default. Ivan S · pexels · Pexels License

The disclosure timeline

AIR says it found the bug in May 2026, with working proof-of-concept exploits against all four agents, and reported it to each vendor the following month. Public disclosure came on 18 September — roughly four months after discovery, and after two of the four vendors had shipped fixes.

The researchers argue this is the first genuine supply-chain vulnerability in the AI agent ecosystem, rather than a prompt-injection problem dressed up as one. The distinction matters: prompt injection attacks the model’s judgement, while this attacks the distribution channel underneath it, and the model never gets a say.

For teams running Claude Code or Codex, updating past the fixed versions closes it. For Copilot users, there is currently nothing to update to.