My brother has been extensively using AI coding agents in his workflow. He usually pins his Claude Code plugins to a specific commit hash because he knows that’s the safe way to do it. Lock the version, trust the review, move on. That’s the whole deal with SHA pinning.
But when I read that a bug named Plugin4Shell is out there quietly exploiting the plugin, I went ahead and warned him to check his plugin list.
Plugin4Shell is a zero-click remote code execution flaw disclosed on September 17, 2026, by security researchers at AIR Security. It affects four of the most widely used AI coding agents: Claude Code, OpenAI’s Codex, GitHub Copilot, and Gemini CLI. The scary part is that it works by exploiting a gap nobody thought to check.
TL;DR: Plugin4Shell lets an attacker who controls a plugin’s repository swap in malicious code while the agent still believes it installed the reviewed, pinned version. No click, no approval, and no reinstall needed. Anthropic patched Claude Code in version 2.1.179, and OpenAI patched Codex in 0.146.0. GitHub Copilot had no fix at disclosure, and Google is retiring the affected Gemini CLI instead of fixing it.
What Plugin4Shell actually breaks?
SHA pinning is supposed to be the boring, reliable part of plugin security. A marketplace reviews a plugin, locks it to one specific 40-character commit hash, and from then on that hash is the only version anyone is supposed to get. Change the code, change the hash, no exceptions.
Researchers Or Nevo, Dor Granat, and Niv Hoffman at AIR Security found that the four affected agents check out the pinned commit but never confirm the checkout actually landed on that exact hash afterward. That gap is the entire vulnerability.
An attacker who controls the plugin’s repository can create a branch named exactly like the pinned SHA, or, in some implementations, name a branch FETCH_HEAD, and set it as the default branch.
The agent’s checkout resolves to that branch instead of the commit the developer thought was locked in. The pin still looks honored. It isn’t.
| Agent | Affected | Fixed version | Status at disclosure |
|---|---|---|---|
| Claude Code | Yes | 2.1.179 | Patched |
| OpenAI Codex | Yes | 0.146.0 | Patched |
| GitHub Copilot | Yes | — | No fix at disclosure |
| Gemini CLI | Yes | — | Deprecated, no fix planned |
Why does this count as zero-click?
Most exploits still need a person to do something wrong. Open the file, click the link, approve the prompt. Plugin4Shell skips all of that because agents auto-update installed plugins by default.
You installed a plugin once. It passed review, and everything was fine. Weeks later, the agent quietly pulls an update in the background, the same git checkout logic runs again, and this time it resolves to the attacker’s branch instead of the version you actually approved.
You never see a prompt. You never click anything. The malicious code just shows up the next time the agent refreshes its plugins.
That’s what makes this different from a typical supply chain scare. You didn’t skip a warning or ignore a permission request. The system did exactly what it was supposed to do, but the design had a hole in it.
Two ways an attacker actually pulls this off
AIR Security laid out two practical paths of an attacker’s modus operandi. The first way involves submitting a plugin that looks completely ordinary, and letting it pass marketplace review. It is followed by later changing the repository so the same pinned reference resolves somewhere else.
The second method is sort of opportunistic, which involves taking over an existing, already trusted plugin’s repository, something the same researchers demonstrated earlier this year in what they called SkillJacking and RepoJacking.
Either path ends the same way. The marketplace still shows a green checkmark next to a reviewed commit hash, and the agent still believes it’s running that exact code.
Current status of the AI coding agents
Anthropic shipped a fix in Claude Code 2.1.179. If you’re running an older build, that spinner in your terminal has been quietly pulling plugin updates through the exact logic this bug exploits. OpenAI’s fix landed in Codex 0.146.0.
GitHub said it added a mitigation that stops one variant of the attack on its own platform, but AIR Security told The Register that isn’t enough, since Copilot also pulls plugins from marketplaces hosted on other platforms like Bitbucket, which GitHub’s fix doesn’t touch.
Google’s response was different again. Gemini CLI is being deprecated, and Google is directing users toward its newer Antigravity tool instead of patching the flaw.
If Copilot were my daily driver, I’d turn off automatic plugin updates until an actual fix lands, not just a mitigation with a documented gap in it.
No evidence of real-world attacks is not the same as safe
AIR Security disclosed working proof-of-concept exploits against all four agents, and none of the reporting so far claims Plugin4Shell was used in an actual attack before it went public. It’s also not much comfort.
The researchers found the bug in May 2026 and disclosed it to vendors the following month, months before telling the public. The flaw sat there, exploitable, before most people using these tools ever heard the word Plugin4Shell.
What actually changes if you use one of these tools?
If you’re on Claude Code or Codex, updating to the patched versions closes this specific hole. If you’re on Copilot or Gemini CLI, the calculation is less comfortable.
A plugin you already trust, sitting quietly in your setup, could theoretically be swapped out from underneath you the next time it auto-updates. Checking which marketplaces your plugins actually come from, and whether auto-update can be disabled in the meantime, isn’t overkill here.
Frequently Asked Questions
Is Claude Code still vulnerable to Plugin4Shell?
No. Anthropic fixed the flaw in Claude Code version 2.1.179, so anyone running that version or newer is protected.
What about GitHub Copilot?
Copilot had no client fix at the time of disclosure. GitHub added a mitigation on its own platform, but researchers say it does not cover plugins hosted on other services like Bitbucket.
Do I need to click something for Plugin4Shell to affect me?
No. The flaw triggers through an agent’s normal background plugin auto-update, so no click, approval, or reinstall is needed.
Has Plugin4Shell actually been used in an attack?
No confirmed real-world attacks have been reported. AIR Security disclosed working proof-of-concept exploits, not evidence of active exploitation before disclosure.
Should I turn off plugin auto updates?
If you are on an unpatched agent like Copilot or Gemini CLI, disabling automatic plugin updates until a fix lands is a reasonable precaution.
The part that outlasts this vulnerability
What actually got exposed here wasn’t a line of bad code in one product. It was a shared assumption that pinning a hash to a commit means you’ll always get that exact commit back.
Nobody added the one extra check that would have caught the gap, because the whole industry treated pinning as the finished solution.
That’s a pattern worth remembering the next time a new AI tool ships a security feature with a reassuring name. The brand name isn’t the guarantee. It is the verification underneath that matters.






