ZeroHour
Organization

AIR

3 mentions in 7 days · 3 in 30 days · 3 total · first seen · last

Timeline

A zero-click RCE flaw in AI coding agents could have exposed enterprise systemsnew

Researchers disclosed Plugin4Shell, a zero-click RCE in Claude Code, Codex, Gemini CLI, and Copilot caused by unverified Git plugin checkouts.

Researchers at AIR found that AI coding agents pass Git commit SHAs to check out plugins without verifying Git actually checked out the reviewed commit, letting attackers who control a plugin repository serve malicious code instead. Claude Code 2.1.179 and Codex 0.146.0 are patched; Google deprecated Gemini CLI without a fix, and GitHub Copilot remains unpatched. The zero-click attack, discovered in May and disclosed to vendors in June, could expose source code, API keys, cloud credentials, and CI/CD systems in enterprise environments.

Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched

Researchers disclosed Plugin4Shell, a zero-click RCE SHA-pinning bypass in Claude Code, Codex, GitHub Copilot, and Gemini CLI; two remain unpatched.

AIR researchers found Plugin4Shell in May 2026: all four major AI coding agents check out SHA-pinned plugin commits without verifying the checkout landed there, letting attackers swap in malicious code while the pin appears intact. Background auto-updates in Claude Code and Codex make the attack zero-click, and threat paths include backdooring a legitimate plugin or hijacking a trusted repository, as shown by AIR's SkillJacking research where 925 hijacked skills reached 134,000 agents. Anthropic fixed Claude Code in version 2.1.179 and OpenAI fixed Codex in 0.146.0, while Microsoft has shipped no Copilot fix and Google deprecated Gemini CLI without patching, directing users to Antigravity.

Help Net Securityupdated · 30m agofirst · 7h agoVulnerability 10 sources2· 2 reads

AI coding agents' 0-click RCE flaw could hand attackers keys to the kingdom

Researchers disclosed Plugin4Shell, a zero-click RCE in major AI coding agents' plugin SHA-pinning; Anthropic and OpenAI patched, Microsoft and Google did not.

Air researchers disclosed Plugin4Shell, a plugin SHA-pinning bypass enabling zero-click remote code execution in major AI coding agents including Claude Code, OpenAI Codex, Gemini CLI, Microsoft Copilot, and GitHub Copilot. The agent checks out the commit a marketplace pinned but never verifies it, letting an attacker who controls the plugin repo make the checkout resolve to malicious code, and plugin auto-updates make the attack zero-click. Anthropic patched in Claude Code 2.1.179 and OpenAI in Codex 0.146.0 after June reports; Google deprecated Gemini CLI without a fix, and Microsoft has not patched Copilot, while Air disputes GitHub's SHA-naming mitigation as insufficient since Bitbucket-hosted marketplaces remain exposed.

The Register · Securityupdated · 30m agofirst · 17h agoVulnerability 10 sources2· 1 read