Safety and security · Agents · Anthropic
Plugin4Shell flaw found in four AI coding agents
This story was corrected after publication (Oct. 9, 2026). Details

On September 17, AIR Security researchers Or Nevo, Dor Granat and Niv Hoffman published a flaw they named Plugin4Shell. The same flaw sits in four coding agents at once: Claude Code, OpenAI Codex, GitHub Copilot and Gemini CLI.
The researchers call it “the first supply chain vulnerability of the AI agent ecosystem.”
Plugin marketplaces pin every plugin to a specific Git commit hash for safety. The agents fetch that hash but never verify that the code they received is actually that commit.
An attacker creates a branch named with the same 40-character hash and makes it the default. Git prefers the branch, and the malicious code installs with a “successfully installed” message.
What makes it zero-click is auto-update. Claude Code and Codex update installed plugins in the background on their own; the user does not have to do anything.
AIR’s warning: “Doing the right thing does not protect you.” Installing a reviewed, pinned plugin from a trusted marketplace is enough to be exposed.
The four agents are not in the same place. Anthropic and OpenAI shipped fixes. GitHub Copilot has no patch; GitHub blocks hash-like branch names on its own platform, but Copilot can also install plugins from other hosts, and Bitbucket and self-hosted git servers do not have that protection.
Google has retired Gemini CLI and will not patch it, pointing users to Antigravity instead.
AIR found the flaw in May, reported it to the four vendors in June and published on September 17. There is no evidence of exploitation in the wild, and no CVE has been assigned.
The skeptical reading: according to The Hacker News, background auto-update is the default only on the agents’ built-in GitHub-hosted marketplaces, and GitHub does not allow hash-like branch names. So the zero-click scenario applies to third-party marketplaces.
Sources
- AIR Security, “Plugin4Shell - Zero Click RCE Vulnerability found in top 4 most popular coding agents, millions of agents affected”, (air.security)
- The Hacker News, “Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents”, (thehackernews.com)
- Google Developers Blog, “An important update: Transitioning Gemini CLI to Antigravity CLI”, (developers.googleblog.com)
Corrections and updates
- The version first posted on Instagram said GitLab and Bitbucket lack the protection against hash-like branch names. GitLab blocks such names too; according to AIR, the gap is on Bitbucket and self-hosted git servers, and the text has been corrected.
About this story
This story was posted on Instagram by @jarrus.tech on Sept. 20, 2026.
Spotted an error in this story? [email protected] · Instagram
Short link: thejarrus.com/en/c5
This story in Turkish: Plugin4Shell açığı dört yapay zeka kodlama ajanında bulundu
On the same topic
Anthropic releases Claude Haiku 5.5 at 90% lower prices
Claude Haiku 5.5, released Oct. 7, costs 90% less than Haiku 4.5 for prompts up to 100,000 tokens. It leads on benchmarks but uses more tokens per task.
OpenAI is rolling out GPT-6 to everyone in ChatGPT
OpenAI began rolling out GPT-6 to everyone in ChatGPT on October 7. Its new Intelligent UI builds answers from text, visuals and interactive elements.
OpenAI’s unreleased model wrote 722 math papers
On October 6, OpenAI published 722 math papers from an unreleased internal model on GitHub. It withdrew three on October 7, leaving 719 in the catalog.