Hacker News
Plugin4Shell: One SHA-Pinning Bug Gives Zero-Click RCE in Claude Code, Codex, Copilot and Gemini CLI
Security firm AIR publicly disclosed Plugin4Shell on 17-18 September 2026: all four major coding agents check out a marketplace-pinned commit but never verify the checkout actually landed on that SHA, so a repo owner can swap in malicious code while the pin still looks honored. Anthropic patched Claude Code in 2.1.179 and OpenAI patched Codex in 0.146.0; Microsoft has shipped no Copilot fix and Google deprecated Gemini CLI rather than patching it, leaving existing installs exposed indefinitely. AIR found the bug in May 2026 with working exploits against all four, reported it in June, and says 925 compromised skills reached 134,000 agents in its test.
↳ Follow the thread