Plugin4Shell: SHA-pinning bypass → zero-click RCE in Claude Code, Codex, Copilot, Gemini CLI (AIR)
AIR Security (Or Nevo, Dor Granat, Niv Hoffman; 17 September 2026) discloses Plugin4Shell: a marketplace plugin SHA-pinning bypass affecting the four major AI coding agents — Anthropic Claude Code, OpenAI Codex, GitHub Copilot, and Google Gemini CLI. Attack path: a trusted plugin/skill repo is compromised (building on prior SkillJacking findings); the agent checks out the pinned commit but does not verify the tree that landed, so checkout can resolve to malicious code while the pin still appears honoured — zero-click RCE on the developer host with the employee’s full reach into enterprise systems. No CVE identifier published in the disclosure. Patches named by AIR: Claude Code 2.1.179 (Anthropic); Codex 0.146.0 (OpenAI). GitHub Copilot: disclosed to Microsoft, no patch shipped at publication — users have no vendor fix yet. Gemini CLI: Google deprecated the CLI and will not patch; AIR advises migrating to Antigravity (no marketplace SHA-pinning surface). Enterprises using Air Marketplace / Air Filter were not affected per the authors. Treat community agent plugins as untrusted code until agents verify checkout integrity.
- Product
- AI coding agents: Claude Code, OpenAI Codex, GitHub Copilot, Google Gemini CLI (marketplace plugins/skills)
- Versions
- Fixed where shipped: Claude Code 2.1.179+; Codex 0.146.0+. Copilot: unpatched at disclosure. Gemini CLI: will not be patched (deprecated).
- Exploited in Australia?
- unknown
- Patch to
- Upgrade Claude Code to 2.1.179+ and Codex to 0.146.0+; restrict Copilot marketplace plugins until Microsoft ships a fix; migrate off Gemini CLI; prefer vetted enterprise plugin sources over public marketplaces.
