
A security flaw called Plugin4Shell lets attackers slip malicious code into the four most widely used AI coding agents without any click from the user. Affected are Anthropic’s Claude Code, OpenAI’s Codex, Microsoft’s GitHub Copilot, and Google’s Gemini CLI – the tools millions of developers rely on every day to generate, revise, and run code. The flaw breaks the very mechanism meant to make plugins tamper-proof: pinning them to a reviewed version. Two of the four vendors have responded. Two have not.
Key takeaways
- Security firm Air Security discovered the flaw in May 2026 and published its findings on September 17, 2026, after notifying all four vendors in June.
- The bug breaks so-called SHA pinning: agents check which commit a plugin marketplace specifies, but never verify that this exact commit is what actually gets checked out.
- Anthropic patched Claude Code in version 2.1.179, OpenAI patched Codex in version 0.146.0.
- GitHub Copilot remains unpatched, and Google will not fix the consumer version of Gemini CLI at all, instead recommending a move to the newer Antigravity CLI.
- No exploitation in the wild is known so far, and no official CVE identifier has been assigned yet.
How the attack works
Plugin marketplaces for AI coding agents work much like app stores: a developer submits an extension, the platform reviews the code once, and then pins it to a specific commit hash – a 40-character checksum that uniquely identifies one version of the source. That exact guarantee is what Plugin4Shell breaks. According to the researchers at Air Security, all four agents check out the pinned commit, but never verify that this is actually the commit that landed. For Claude Code, Codex, and Copilot, a simple trick suffices: whoever controls a Git repository creates a branch whose name exactly matches the pinned commit checksum and sets it as the default branch. When checking out, Git then prefers that branch over the actual commit ID, surfacing only an inconspicuous warning about an ambiguous reference in the background. The agent keeps reporting the correctly pinned version while actually running the attacker’s code. Gemini CLI is exploited differently: when someone pins a plugin via the „–ref“ parameter, the referenced commit lands in an internal reference called FETCH_HEAD – and if the repository’s default branch happens to be named the same way, the tool checks that out instead of the commit that was actually meant.
The impact is severe because extensions typically run with the same permissions as the agent itself, and the agent in turn runs with the permissions of whoever launched it. A malicious plugin update therefore gains access to local source code, cloud credentials, SSH keys, internal repositories, and sometimes production systems, without anyone having to click a warning, confirm a reinstall, or notice anything at all. Air Security calls the finding the first supply-chain attack of the AI agent ecosystem. One important nuance: the official, GitHub-based default marketplaces for Claude Code and Copilot are not vulnerable to the simplest attack path, because GitHub forbids branch names that look like commit hashes. What remains exposed are extensions hosted on Bitbucket, GitLab, or self-hosted Git servers, where that protection does not exist – and all four agents allow exactly those external sources.
Who has patched it – and who has not
Anthropic moved fastest: just days after the confidential disclosure, Claude Code shipped version 2.1.179 with the fix on June 16, 2026. OpenAI confirmed its fix in Codex version 0.146.0 in early August. Microsoft’s GitHub Copilot, by contrast, still has no fixed version available, even though the company was notified back in June – a statement from GitHub on the reasons remains outstanding. Google, meanwhile, decided in August not to patch the consumer version of Gemini CLI at all: the tool is being phased out, and users are instead urged to move to the newer Antigravity CLI, which as of now appears to lack a comparable SHA-pinning mechanism for marketplace plugins. Enterprise access through Gemini Code Assist and Google Cloud is unaffected, since it relies on a different architecture.
Why this is more than a footnote
How seriously vendors now have to take control over automated coding agents was underscored just this week by Google’s move to put AI agents in front of every code check-in – a step that would be undermined entirely if the plugin layer of the agents themselves can be subverted. The recent RoboHarm study, in which most AI models went along with unsafe instructions once they were given control of a robot, had already shown how quickly agentic tools can become the security risk themselves once they are granted far-reaching permissions. Plugin4Shell adds a new dimension: this time, it does not even take a compromised agent or a manipulated prompt – a single, later-hijacked plugin repository is enough to reach thousands of developer environments at once.
What developers should do now
There is still no CVE identifier for Plugin4Shell, and no known case of exploitation – both reasons why the flaw has so far been discussed mostly among security researchers rather than the wider public. That should not be reassuring. Anyone using Claude Code, Codex, or Copilot with extensions from external marketplaces should update to the patched versions immediately and review existing plugin installations from non-GitHub sources. Copilot users, until a fix ships, have little choice but to avoid extensions from untrusted sources altogether. Gemini CLI users should not delay the recommended move to Antigravity. More broadly, the case makes one thing clear: the more permissions developers hand to their AI agents, the more carefully every single extension needs to be vetted – a reviewed and pinned plugin is only ever as safe as the mechanism that actually enforces the pinning.

