started · updated
Plugin4Shell vulnerability affects major AI coding agents
Researchers at Air have identified a critical security vulnerability named ‘Plugin4Shell’ that affects several major AI coding agents, including Claude Code, Codex, Gemini CLI, and Microsoft Copilot.
The vulnerability targets the mechanism agents use to verify plugin integrity via SHA-pinning. By exploiting this, attackers can bypass verification to inject malicious code into plugins. Because these agents often update plugins automatically, the flaw presents a ‘zero-click’ threat, potentially allowing unauthorized access to developer machines and sensitive corporate data.
In response to the discovery, Anthropic has patched Claude Code (version 2.1.179) and OpenAI has patched Codex (version 0.146.0). Google has opted to deprecate the affected Gemini CLI in favor of its new tool, Antigravity, rather than issuing a patch. Microsoft has not yet released a fix for Copilot.