Skip to content
Türkçe

Safety and security · Agents · Anthropic

Plugin4Shell flaw found in four AI coding agents

Published: Updated: 3 sourcesTürkçe

This story was corrected after publication (Oct. 9, 2026). Details

AI-generated image.

On September 17, AIR Security researchers Or Nevo, Dor Granat and Niv Hoffman published a flaw they named Plugin4Shell. The same flaw sits in four coding agents at once: Claude Code, OpenAI Codex, GitHub Copilot and Gemini CLI.

The researchers call it “the first supply chain vulnerability of the AI agent ecosystem.”

Plugin marketplaces pin every plugin to a specific Git commit hash for safety. The agents fetch that hash but never verify that the code they received is actually that commit.

An attacker creates a branch named with the same 40-character hash and makes it the default. Git prefers the branch, and the malicious code installs with a “successfully installed” message.

What makes it zero-click is auto-update. Claude Code and Codex update installed plugins in the background on their own; the user does not have to do anything.

AIR’s warning: “Doing the right thing does not protect you.” Installing a reviewed, pinned plugin from a trusted marketplace is enough to be exposed.

The four agents are not in the same place. Anthropic and OpenAI shipped fixes. GitHub Copilot has no patch; GitHub blocks hash-like branch names on its own platform, but Copilot can also install plugins from other hosts, and Bitbucket and self-hosted git servers do not have that protection.

Google has retired Gemini CLI and will not patch it, pointing users to Antigravity instead.

AIR found the flaw in May, reported it to the four vendors in June and published on September 17. There is no evidence of exploitation in the wild, and no CVE has been assigned.

The skeptical reading: according to The Hacker News, background auto-update is the default only on the agents’ built-in GitHub-hosted marketplaces, and GitHub does not allow hash-like branch names. So the zero-click scenario applies to third-party marketplaces.

Sources

  1. AIR Security, “Plugin4Shell - Zero Click RCE Vulnerability found in top 4 most popular coding agents, millions of agents affected”, (air.security)
  2. The Hacker News, “Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents”, (thehackernews.com)
  3. Google Developers Blog, “An important update: Transitioning Gemini CLI to Antigravity CLI”, (developers.googleblog.com)

Corrections and updates

  1. The version first posted on Instagram said GitLab and Bitbucket lack the protection against hash-like branch names. GitLab blocks such names too; according to AIR, the gap is on Bitbucket and self-hosted git servers, and the text has been corrected.

About this story

This story was posted on Instagram by @jarrus.tech on Sept. 20, 2026.

Spotted an error in this story? [email protected] · Instagram

This story in Turkish: Plugin4Shell açığı dört yapay zeka kodlama ajanında bulundu

On the same topic