Air disclosed Plugin4Shell, a zero-click remote-code-execution supply-chain flaw in plugin marketplaces used by major AI coding agents. The vulnerability can bypass plugin SHA pinning by causing a repository checkout pinned to an ostensibly immutable commit hash to resolve to attacker-controlled code, allowing a malicious plugin submission—or compromise of a legitimate plugin author's repository—to deliver code to installed agents.
Default plugin auto-updates make exploitation zero-click in Claude Code and OpenAI Codex, potentially granting attackers access to developer environments, source code, credentials, and connected infrastructure. Anthropic and OpenAI patched affected products; Air said Microsoft Copilot remains vulnerable and deprecated Gemini CLI installations will not be patched, while GitHub disputed that its platform can be exploited using the reported technique.

Track how attackers are adapting to this technology.
9 events from the most recent confirmed update back to the earliest known activity.
AIR discovered the Plugin4Shell zero-click remote-code-execution vulnerability affecting AI coding-agent plugin update mechanisms in May 2026.
Air Security reported a separate Plugin4Shell technique for Gemini CLI involving a repository whose main branch is named FETCH_HEAD. GitHub's block on commit-hash-like branch and tag names may not prevent this variant.
GitHub stated that Plugin4Shell does not affect GitHub because it blocks branch and tag names resembling commit SHAs. Air disputed that this mitigated the broader issue because agent marketplaces can also use platforms such as Bitbucket.
Microsoft had not issued a fix for Plugin4Shell in GitHub Copilot at the time the vulnerability was disclosed.
Google told Air it would not patch the flaw in deprecated Gemini CLI, leaving existing installations vulnerable. Google recommended users migrate to its Antigravity agentic development environment, which it said is protected from the attack.
OpenAI patched the Plugin4Shell issue in Codex version 0.146.0.
Anthropic patched the Plugin4Shell issue in Claude Code version 2.1.179.
Air researchers Or Nevo, Dor Granat, and Niv Hoffman disclosed Plugin4Shell, a supply-chain vulnerability affecting plugin marketplaces for Claude Code, OpenAI Codex, Gemini CLI, and Microsoft Copilot. The flaw can cause a pinned plugin checkout to resolve to attacker-controlled code and, where plugins auto-update, enable zero-click remote code execution.
Air reported the Plugin4Shell plugin SHA-pinning bypass vulnerability to Anthropic, OpenAI, Google, and Microsoft in June. The source does not specify a year for the report.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
11 references tracked. Mallory keeps watching after this page renders.
heise.de
Open sourcecysecurity.news
Open sourceinfoworld.com
Open sourcethehackernews.com
Open sourcetheregister.com
Open sourceair.security
Open sourceair.security
Open sourcecode.claude.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.