Zero-click RCE flaw in AI coding assistants threatens millions of users
Researchers have uncovered a zero-click remote code execution vulnerability, called Plugin4Shell, that affects major AI coding agents such as Claude Code, Codex, Gemini CLI, Copilot and GitHub Copilot.
Threat-hunting firm Air reported a novel supply-chain attack named Plugin4Shell that enables zero-click remote code execution across the leading AI coding assistants, including Anthropic’s Claude Code, OpenAI’s Codex, Google’s Gemini CLI, Microsoft’s Copilot and GitHub Copilot. The exploit sidesteps the SHA-pinning mechanism used by plugin marketplaces, letting an attacker replace a trusted plugin with malicious code after it has been approved.
Anthropic and OpenAI responded with patches (Claude Code 2.1.179 and Codex 0.146.0), while Google chose to retire the Gemini CLI and recommend its Antigravity environment. Microsoft has not yet patched Copilot, and GitHub’s protective measure against SHA-like names is deemed insufficient. If left unaddressed, the vulnerability could grant attackers full control over any assets accessible to the compromised agents, affecting potentially millions of Fortune 500 users.
Why it matters
The flaw could let attackers hijack AI coding tools and access sensitive corporate data worldwide.
In this story
