Trending
← Back to live feed · 1 stories across 1 day
Sunday, Sep 20, 2026
1 story1 Plugin4Shell Zero Click RCE Hits 4 AI Agents Including Copilot and Gemini CLI AI Sep 20, 10:00 AM EDT 5/4
1
Plugin4Shell Zero Click RCE Hits 4 AI Agents Including Copilot and Gemini CLI
AI Sep 20, 10:00 AM EDT 5/4
topics 🔒
Cybersecurity🤖
AI tags AIAI RegulationAI LegalTechCybersecurityAI ProductsAI Agents keywords ◇
Claude Code, Codex, Copilot, and Gemini CLI contained a zero click remote code execution flaw that bypassed security verification for third party plugins. The vulnerability, named Plugin4Shell, allowed attackers to replace a pinned plugin commit with malicious code that executed with full developer permissions on a user's machine by breaking SHA pinning.
Claude Code and Codex released patches for the vulnerability, which requires an attacker to have control of the plugin repository to succeed. The flaw exposes security risks in the AI agent supply chain by allowing malicious code to be injected into tools after users have already downloaded the software.
Earlier version from Sunday, Sep 20
Plugin4Shell Zero Click Flaw Hits 4 AI Coding Agents Including Copilot 4 tweets • 3 sources