← Back to live feed · 1 stories across 1 day
Friday, Sep 18, 2026
1 story1 NEWPlugin4Shell Zero Click RCE Hits 4 AI Agents Including GitHub Copilot AI Sep 18, 7:06 AM EDT 3/3
Anthropic, OpenAI, Microsoft, and Google are managing a high-severity security flaw that allows attackers to run unauthorized code through malicious plugin updates. The vulnerability, known as Plugin4Shell, enables zero-click remote code execution by bypassing SHA-pinning on the auto-update path of 4 AI coding agents. Users of Claude Code, OpenAI Codex, GitHub Copilot, and Gemini CLI can have their systems compromised if an attacker controls the underlying plugin repository.
The exploit provides access to local source code, SSH keys, and cloud credentials because plugins inherit the permissions of the agent's developer. Claude Code version 2.1.179 and Codex version 0.146.0 contain fixes for the flaw. GitHub Copilot remains vulnerable, while Google has deprecated the Gemini CLI in favor of Antigravity without providing a patch for the original tool.