A zero-click RCE flaw in AI coding agents could have exposed enterprise systemsnew
Researchers disclosed Plugin4Shell, a zero-click RCE in Claude Code, Codex, Gemini CLI, and Copilot caused by unverified Git plugin checkouts.
Researchers at AIR found that AI coding agents pass Git commit SHAs to check out plugins without verifying Git actually checked out the reviewed commit, letting attackers who control a plugin repository serve malicious code instead. Claude Code 2.1.179 and Codex 0.146.0 are patched; Google deprecated Gemini CLI without a fix, and GitHub Copilot remains unpatched. The zero-click attack, discovered in May and disclosed to vendors in June, could expose source code, API keys, cloud credentials, and CI/CD systems in enterprise environments.