← Back to live feed · 1 stories across 1 day

Saturday, Sep 19, 2026

1 story
1
Plugin4Shell Zero Click RCE Hits 4 AI Agents in First AI Supply Chain Flaw
topics 🔒 Cybersecurity🤖 AI💻 Tech tags AIAI RegulationAI LegalAI ProductsAI AgentsTechCybersecurity keywords GoogleSecurity

Anthropic's Claude Code, OpenAI's Codex, GitHub Copilot, and Google's Gemini CLI share a high-severity security flaw allowing remote code execution. The Plugin4Shell vulnerability targets the software supply chain by bypassing SHA pinning during auto-updates, enabling attackers with repository control to silently install malicious code. These add-ons inherit the developer's permissions, granting access to local source code, SSH keys, and cloud credentials.

Anthropic and OpenAI patched the vulnerability in Claude Code version 2.1.179 and Codex version 0.146.0 following disclosure by Air Security. GitHub Copilot remains unpatched, and the Google Gemini CLI is unpatched and deprecated. The flaw cannot be mitigated by the plugin marketplaces themselves, requiring users to update their agent software to prevent zero click attacks.

Earlier version from Friday, Sep 18
Plugin4Shell RCE Hits 4 AI Agents in First AI Supply Chain Vulnerability
4 tweets • 4 sources
See all 5 tweets →