One Zero-Click Flaw Just Handed Attackers the Keys to Claude Code, Codex, Copilot and Gemini
AIR's Plugin4Shell research, reported 18 September 2026, says Claude Code, Codex, Copilot, and Gemini CLI skip verifying a pinned Git checkout. Claude Code 2.1.179 and Codex 0.146.0 are patched. Copilot was not. Google deprecated Gemini CLI.

Help Net Security (Sinisa Markovic, 18 September 2026) reported that cybersecurity startup AIR disclosed a zero-click remote code execution flaw it calls Plugin4Shell in four AI coding agents: Anthropic Claude Code, OpenAI Codex, Microsoft GitHub Copilot, and Google Gemini CLI. CSO Online (Anirban Ghoshal) carried the same research.
This is an independent research disclosure from AIR. It is not a claim that every enterprise was breached. Help Net Security and CSO described the bug as Plugin4Shell and did not assign a CVE identifier in those reports.
AIR says each agent checks out a pinned Git commit without verifying the checkout landed on that commit. An attacker who controls the plugin repo can swap malicious code while the pin still looks intact. The trick works where a branch can be named like a hash. GitHub rejects 40-character hex branch names, while Bitbucket and self-hosted Git often allow them.
The zero-click path is background auto-update, the default on Claude Code and Codex. When a marketplace bumps the pinned SHA, the same checkout runs again, so already-installed plugins get the swap with no user click. AIR calls this the first supply-chain vulnerability of the AI agent ecosystem. A marketplace alone cannot close it, so users have to update the agent.
AIR found the bug in May 2026 with working proof-of-concept attacks against all four agents, and disclosed it to the vendors the following month. At Help Net Security's publish time, Anthropic had patched Claude Code in 2.1.179 and OpenAI had patched Codex in 0.146.0. Microsoft had not shipped a Copilot fix. Google deprecated Gemini CLI rather than patch it and told users to move to Antigravity, which AIR says was built without that plugin pinning system.
CSO, citing GitHub's comment to The Register, said GitHub already blocks version or tag names that look like commit SHAs on its own host. AIR told the same outlet that restriction is not enough, because plugin marketplaces also live on Bitbucket and other Git hosts. A plugin AIR built earlier reached more than 26,000 agents before it was pulled. Separate SkillJacking research found 925 skills hijacked from maintainers, reaching about 134,000 agents.
Related agent and supply-chain tape includes the BragJack browser AI extension hijack, the Brevo ClickFix supply-chain hit on 100,000 sites, and the Cisco ISE login bypass under active exploit.
If you run Claude Code, move to 2.1.179 or later today. If you run Codex, move to 0.146.0 or later. If you run Copilot, disable marketplace plugins until Microsoft ships a fix. If you still run Gemini CLI, migrate to Antigravity or another agent that does not use this pinning path.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free