Plugin4Shell: AI Coding Agents Ignore SHA Pins, Exposing Millions to Supply Chain Attack
Security researchers at AIR have disclosed a vulnerability called Plugin4Shell, which they describe as the first supply chain vulnerability in the AI agent ecosystem, affecting Claude Code, Codex, GitHub Copilot, and Gemini CLI. The flaw allows attackers to substitute malicious code in place of a pinned commit SHA, because none of these agents verify that the checked-out code actually matches the requested commit. The attack requires zero user interaction and can be triggered silently via auto-update features enabled by default in Claude Code and Codex. Anthropic and OpenAI have issued patches, but Microsoft has yet to release a fix for Copilot — used by nearly 90% of Fortune 500 companies — while Google has deprecated Gemini CLI entirely without patching it. Users of unpatched tools remain at risk of attacker-controlled code executing with elevated agent permissions until vendors ship verified checkout logic.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.



Discussion (0)
Log in to join the discussion and vote.
Log in