Theregister Plugin4Shell: Zero-Click RCE Vulnerability in Major AI Coding Agents
Article Content
- •Plugin4Shell allows zero-click RCE in major AI coding agents.
- •The vulnerability affects millions, particularly in Fortune 500 companies.
- •Patches have been issued by some vendors, but others remain vulnerable.
A zero-click remote code execution vulnerability, named Plugin4Shell, affects major AI coding agents including Claude Code, Codex, Copilot, and Gemini. This vulnerability allows attackers to exploit a flaw in the SHA-pinning mechanism of trusted plugin marketplaces, enabling full access to sensitive data and systems without user interaction. The attack method involves silently replacing a trusted plugin with a malicious one, which is then auto-installed, compromising the agent and the host machine. The vulnerability impacts millions of users, particularly in enterprises, as almost 90% of Fortune 500 companies utilize Copilot. While Anthropic and OpenAI have issued patches, Google has deprecated Gemini CLI without a patch, and Microsoft has not addressed the flaw in Copilot. The security issue was reported to the vendors in June 2026. The exploit is significant as it represents a first-of-its-kind AI supply-chain attack targeting the distribution layer of AI agents.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Conti and CVE-2026-76460 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Iranian State Actors Deploy CHOSEN BRICK Spyware Against Dissidents On September 15, 2026, the UK, US, and Netherlands issued a joint advisory regarding a spyware campaign attributed to Iranian state actors targeting dissidents, activists, and journalists. The malware, known as CHOSEN BRICK, is delivered through spear-phishing attacks on messaging platforms like WhatsApp and Telegram.…