← Back to live feed · 1 stories across 1 day

Sunday, Sep 20, 2026

1 story
1
Plugin4Shell Zero Click RCE Bypassed SHA Pinning on 4 Leading AI Agents
topics 🔒 Cybersecurity🤖 AI💻 Tech tags AIAI RegulationAI LegalTechCybersecurityAI ProductsAI Agents keywords Google

Researchers disclosed a zero-click remote code execution vulnerability called Plugin4Shell that affected Claude Code, Codex, GitHub Copilot, and Gemini CLI. The flaw allowed attackers with control of a plugin repository to inject malicious code by bypassing SHA pinning, a security measure intended to lock plugins to specific git commits. Claude Code and Codex issued patches for the vulnerability, while Google deprecated the Gemini CLI instead of fixing it and GitHub Copilot remains unpatched.

The vulnerability enables malicious auto-updates to run with a developer's full system permissions, turning AI agent plugin systems into a vector for software supply chain attacks. These security risks persist as professional workflows rely more heavily on AI assistants and third-party skills that agents failed to verify upon installation on the local disk.

Earlier version from Sunday, Sep 20
Plugin4Shell Zero Click RCE Hits GitHub Copilot and 3 Other AI Agents
7 tweets • 6 sources
See all 7 tweets →