Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agentsnew
Air Security disclosed Plugin4Shell, letting repository owners swap version-locked plugins in Claude Code, Codex, GitHub Copilot, and Gemini CLI.
Air Security found that four widely used AI coding agents fetch version-locked plugin snapshots without verifying the code matches the pinned commit hash, letting repository owners serve different code via a hash-shaped branch name on hosts like Bitbucket or self-hosted git servers. Anthropic fixed the flaw in Claude Code 2.1.179 and OpenAI in Codex 0.146.0; GitHub Copilot has no fix, and Google will not patch the retired consumer Gemini CLI, pointing users to Antigravity. A Gemini CLI variant abuses a main branch named FETCH_HEAD, which GitHub's naming rules do not clearly block. Air reported a working test attack in June 2026; no CVE has been assigned, no vendor advisories exist, and no real-world exploitation has been observed.