Skip to content
Plugin4Shell: Zero-Click RCE Vulnerability in Major AI Coding Agents

Plugin4Shell: Zero-Click RCE Vulnerability in Major AI Coding Agents

First seen 18 Sep 2026, 11:26 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 18, 2026 at 15:58 UTC
  • Plugin4Shell allows zero-click RCE in major AI coding agents.
  • The vulnerability affects millions, particularly in Fortune 500 companies.
  • Patches have been issued by some vendors, but others remain vulnerable.

A zero-click remote code execution vulnerability, named Plugin4Shell, affects major AI coding agents including Claude Code, Codex, Copilot, and Gemini. This vulnerability allows attackers to exploit a flaw in the SHA-pinning mechanism of trusted plugin marketplaces, enabling full access to sensitive data and systems without user interaction. The attack method involves silently replacing a trusted plugin with a malicious one, which is then auto-installed, compromising the agent and the host machine. The vulnerability impacts millions of users, particularly in enterprises, as almost 90% of Fortune 500 companies utilize Copilot. While Anthropic and OpenAI have issued patches, Google has deprecated Gemini CLI without a patch, and Microsoft has not addressed the flaw in Copilot. The security issue was reported to the vendors in June 2026. The exploit is significant as it represents a first-of-its-kind AI supply-chain attack targeting the distribution layer of AI agents.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-06-01
Security issue reported to vendors
Air researchers reported Plugin4Shell vulnerability to all four major AI coding agents' vendors.
The Register
2026-09-17
Plugin4Shell vulnerability disclosed
Air researchers published details of Plugin4Shell, affecting Claude Code, Codex, Copilot, and Gemini CLI.
News.Ycombinator
2026-09-17
Patches released by some vendors
Anthropic and OpenAI patched their respective agents, while Google deprecated Gemini CLI without a patch.
The Register

More articles in this cluster (3)

Following this threat?

Track Conti and CVE-2026-76460 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed