Plugin4Shell flaw lets malicious code silently replace reviewed plugins in AI coding agents

Security research lab AIR has disclosed a vulnerability called Plugin4Shell affecting four AI coding agents — Claude Code, Codex, GitHub Copilot, and Gemini CLI — that allows verified, version-locked plugins to be swapped with malicious code without any user interaction. The flaw exploits a gap in SHA-pinning: agents request a specific reviewed commit hash but never verify that what they receive actually matches it, enabling attackers who control a repository to substitute harmful code via a spoofed branch name. Because Claude Code and Codex perform background updates by default, a compromised plugin can propagate to all installed instances automatically once a marketplace updates its pinned SHA. Anthropic and OpenAI have issued patches in Claude Code v2.1.179 and Codex v0.146.0 respectively, while Microsoft has not yet released a fix for Copilot and Google has opted to discontinue Gemini CLI rather than patch it. Users are advised to update affected agents immediately, as the vulnerability resides in the agent itself and cannot be addressed by any marketplace independently.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in