research
Published 2026-09-17
Verified 2026-09-19

Plugin4Shell: SHA-pinning bypass → zero-click RCE in Claude Code, Codex, Copilot, Gemini CLI (AIR)

AIR Security (Or Nevo, Dor Granat, Niv Hoffman; 17 September 2026) discloses Plugin4Shell: a marketplace plugin SHA-pinning bypass affecting the four major AI coding agents — Anthropic Claude Code, OpenAI Codex, GitHub Copilot, and Google Gemini CLI. Attack path: a trusted plugin/skill repo is compromised (building on prior SkillJacking findings); the agent checks out the pinned commit but does not verify the tree that landed, so checkout can resolve to malicious code while the pin still appears honoured — zero-click RCE on the developer host with the employee’s full reach into enterprise systems. No CVE identifier published in the disclosure. Patches named by AIR: Claude Code 2.1.179 (Anthropic); Codex 0.146.0 (OpenAI). GitHub Copilot: disclosed to Microsoft, no patch shipped at publication — users have no vendor fix yet. Gemini CLI: Google deprecated the CLI and will not patch; AIR advises migrating to Antigravity (no marketplace SHA-pinning surface). Enterprises using Air Marketplace / Air Filter were not affected per the authors. Treat community agent plugins as untrusted code until agents verify checkout integrity.

Product
AI coding agents: Claude Code, OpenAI Codex, GitHub Copilot, Google Gemini CLI (marketplace plugins/skills)
Versions
Fixed where shipped: Claude Code 2.1.179+; Codex 0.146.0+. Copilot: unpatched at disclosure. Gemini CLI: will not be patched (deprecated).
Exploited in Australia?
unknown
Patch to
Upgrade Claude Code to 2.1.179+ and Codex to 0.146.0+; restrict Copilot marketplace plugins until Microsoft ships a fix; migrate off Gemini CLI; prefer vetted enterprise plugin sources over public marketplaces.

Primary: AIR Security — Plugin4Shell (17 Sep 2026)

ai cloud