← Back to live feed · 1 stories across 1 day
Friday, Sep 18, 2026
1 story1 Plugin4Shell RCE Hits 4 AI Agents in First AI Supply Chain Vulnerability AI Sep 18, 7:06 AM EDT 4/4
This flaw affects Claude Code, Codex, Copilot, and Gemini, allowing any trusted plugin in a marketplace to be silently replaced if an attacker controls the plugin repository. Researchers from Air Security identified the zero-click issue as an exploit that enables remote code execution via the software supply chain. Anthropic and OpenAI released patches for the latest versions of Claude Code and Codex following the disclosure.
Plugin4Shell causes coding assistants to install plugin code that differs from the version the software reports as pinned, bypassing integrity checks. This allows the installation of attacker-controlled code without requiring a user to click, approve, or reinstall any extensions. Users are advised to update their agents because the vulnerability cannot be mitigated by the plugin marketplaces themselves.