Zero-click RCE flaw in major AI coding agents risks supply chain attacks

Plugin4Shell exploit affects Claude Code, Codex, Gemini CLI, Microsoft Copilot; patches issued for some but not all

By LineZotpaper
Published
Read Time3 min
A zero-click remote code execution vulnerability dubbed “Plugin4Shell” has been discovered in all major AI coding agents — including Anthropic’s Claude Code, OpenAI’s Codex, Google’s Gemini CLI, and Microsoft’s Copilot — allowing attackers to gain full access to systems via compromised plugin marketplaces, according to researchers at security startup Air.

Threat hunters at Air, a security startup focused on enterprise AI agent protection, have disclosed a first-of-its-kind AI supply-chain attack they call Plugin4Shell. The exploit targets trusted marketplaces that host plugins for popular coding agents rather than the models or agents themselves, potentially reaching millions of users and machines.

The vulnerability lies in how agents enforce SHA-pinning mechanisms designed to lock plugins to a specific immutable commit hash. According to researchers Or Nevo, Dor Granat, and Niv Hoffman, “The agent checks out the exact commit the marketplace pinned but never verifies it landed there, so an attacker who controls the plugin's repo makes the checkout resolve to malicious code while the pin still looks honored. The result is zero-click remote code execution.”

Agents’ plugin auto-update feature makes this a zero-click attack. An attacker could submit a benign plugin to a marketplace, pass review, and later replace the benign content with malicious code, or hijack a legitimate author’s repository and push malicious updates to every agent with the plugin installed.

Air reported the issue to all vendors in June. Anthropic patched Claude Code in version 2.1.179, and OpenAI patched Codex in version 0.146.0. Google told Air it will not patch the Gemini CLI, having deprecated it, and suggests users migrate to its newer Antigravity agentic development environment instead. Microsoft did not fix the flaw in Copilot. A GitHub spokesperson said the attacks do not affect GitHub, stating “To prevent abuse of SHAs, GitHub does not allow users to create branch or tag names that resemble commit SHAs. This mitigation ensures the reported vulnerability cannot be exploited on GitHub.”

Air researchers countered that the GitHub mitigation is insufficient “because marketplaces can also be hosted in other platforms such as Bitbucket.” The team added, “Microsoft Copilot is also still vulnerable because it supports marketplaces from such platforms as well, which exposes it to the vulnerability.” They reported the issue to Microsoft in June but said they did not receive a response due to the volume of disclosures Microsoft is currently handling. Microsoft did not immediately respond to a request for comment.

The researchers described the exploit as affecting almost 90 percent of Fortune 500 companies that use Copilot, according to Microsoft. They emphasized that “the fix has to ship in the agent, and updating is the only complete mitigation where one exists.”

§

Analysis

Why This Matters

  • AI coding agents are increasingly embedded in enterprise development pipelines, making a zero-click RCE flaw a direct threat to source code, credentials, and production infrastructure.
  • The attack targets supply-chain trust mechanisms used by all major agent vendors, meaning the same fundamental weakness may recur across other agent-based tools.
  • No complete fix exists for Microsoft Copilot and Google's deprecated Gemini CLI, leaving a large number of corporate users exposed unless they manually update or migrate.

Background

Plugin ecosystems for development tools are common attack surfaces. SHA-pinning is a standard security practice that ties software components to a specific hash of their code to prevent tampering. This vulnerability bypasses that protection by exploiting the gap between what the marketplace advertises and what the agent actually checks out. AI coding agents auto-update plugins by default, which turns a theoretical bypass into a practical, zero-click exploit.

Key Perspectives

Security researchers (Air): The flaw is a serious, first-of-its-kind supply-chain vulnerability affecting all major agents. Patching is the only complete mitigation, and Microsoft's failure to respond or patch is concerning given Copilot's widespread enterprise adoption. Vendors (Anthropic, OpenAI): These companies have acknowledged the issue and shipped patches in their latest agents. They encourage users to update to protected versions. GitHub/Microsoft: GitHub says its own platform is not vulnerable due to SHAs being protected from misuse. Microsoft has not publicly addressed the vulnerability in Copilot. Critics note that the attack can still work via other platforms Copilot supports. Google: Has deprecated Gemini CLI and will not patch it, urging users to migrate to a protected environment. This leaves existing installations permanently vulnerable.

What to Watch

  • Whether Microsoft issues a patch for Copilot or clarifies its position on the vulnerability.
  • Adoption rates of the patched versions by enterprises using Claude Code and Codex.
  • Potential disclosure of similar vulnerabilities in other agent platforms that use SHA-pinning without verification.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.