Air disclosed Plugin4Shell, a zero-click remote-code-execution supply-chain flaw in plugin marketplaces used by major AI coding agents. The vulnerability can bypass plugin SHA pinning by causing a repository checkout pinned to an ostensibly immutable commit hash to resolve to attacker-controlled code, allowing a malicious plugin submission—or compromise of a legitimate plugin author's repository—to deliver code to installed agents.
Default plugin auto-updates make exploitation zero-click in Claude Code and OpenAI Codex, potentially granting attackers access to developer environments, source code, credentials, and connected infrastructure. Anthropic and OpenAI patched affected products; Air said Microsoft Copilot remains vulnerable and deprecated Gemini CLI installations will not be patched, while GitHub disputed that its platform can be exploited using the reported technique.

Trace attribution and downstream blast radius.
6 events from the most recent confirmed update back to the earliest known activity.
GitHub stated that Plugin4Shell does not affect GitHub because it blocks branch and tag names resembling commit SHAs. Air disputed that this mitigated the broader issue because agent marketplaces can also use platforms such as Bitbucket.
Google told Air it would not patch the flaw in deprecated Gemini CLI, leaving existing installations vulnerable. Google recommended users migrate to its Antigravity agentic development environment, which it said is protected from the attack.
OpenAI patched the Plugin4Shell issue in Codex version 0.146.0.
Anthropic patched the Plugin4Shell issue in Claude Code version 2.1.179.
Air researchers Or Nevo, Dor Granat, and Niv Hoffman disclosed Plugin4Shell, a supply-chain vulnerability affecting plugin marketplaces for Claude Code, OpenAI Codex, Gemini CLI, and Microsoft Copilot. The flaw can cause a pinned plugin checkout to resolve to attacker-controlled code and, where plugins auto-update, enable zero-click remote code execution.
Air reported the Plugin4Shell plugin SHA-pinning bypass vulnerability to Anthropic, OpenAI, Google, and Microsoft in June. The source does not specify a year for the report.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
theregister.com
Open sourceair.security
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.