ZeroHour
Vendor

Bitbucket

1 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched

Researchers disclosed Plugin4Shell, a zero-click RCE SHA-pinning bypass in Claude Code, Codex, GitHub Copilot, and Gemini CLI; two remain unpatched.

AIR researchers found Plugin4Shell in May 2026: all four major AI coding agents check out SHA-pinned plugin commits without verifying the checkout landed there, letting attackers swap in malicious code while the pin appears intact. Background auto-updates in Claude Code and Codex make the attack zero-click, and threat paths include backdooring a legitimate plugin or hijacking a trusted repository, as shown by AIR's SkillJacking research where 925 hijacked skills reached 134,000 agents. Anthropic fixed Claude Code in version 2.1.179 and OpenAI fixed Codex in 0.146.0, while Microsoft has shipped no Copilot fix and Google deprecated Gemini CLI without patching, directing users to Antigravity.

Help Net Securityupdated · 1h agofirst · 8h agoVulnerability 10 sources2· 2 reads

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.