Beta The Briev beta is out. Free on iPhone via TestFlight — install it in under a minute.

Join the beta ↗
Briev
Live
Technology
UNDERREPORTED

Zero-click RCE flaw in AI coding assistants threatens millions of users

Researchers have uncovered a zero-click remote code execution vulnerability, called Plugin4Shell, that affects major AI coding agents such as Claude Code, Codex, Gemini CLI, Copilot and GitHub Copilot.

Threat-hunting firm Air reported a novel supply-chain attack named Plugin4Shell that enables zero-click remote code execution across the leading AI coding assistants, including Anthropic’s Claude Code, OpenAI’s Codex, Google’s Gemini CLI, Microsoft’s Copilot and GitHub Copilot. The exploit sidesteps the SHA-pinning mechanism used by plugin marketplaces, letting an attacker replace a trusted plugin with malicious code after it has been approved.

Anthropic and OpenAI responded with patches (Claude Code 2.1.179 and Codex 0.146.0), while Google chose to retire the Gemini CLI and recommend its Antigravity environment. Microsoft has not yet patched Copilot, and GitHub’s protective measure against SHA-like names is deemed insufficient. If left unaddressed, the vulnerability could grant attackers full control over any assets accessible to the compromised agents, affecting potentially millions of Fortune 500 users.

Why it matters

The flaw could let attackers hijack AI coding tools and access sensitive corporate data worldwide.

In this story

Plugin4Shellzero-clickremote code executionAI coding agentsplugin SHA-pinningsupply-chain attackpatchvulnerability
Get the beta ↗