Plugin4Shell RCE Flaw Hit 26,000 AI Coding Agents via Git Checkout Bypass
Researchers at Air Security discovered in May 2026 that a zero-click remote code execution vulnerability, dubbed Plugin4Shell, affected Claude Code, OpenAI Codex, GitHub Copilot, and Google Gemini CLI. The flaw exploited a gap in how these agents handle plugin updates: they pin plugins to a specific git commit SHA but fail to verify the checked-out code actually matches that commit, allowing attackers to substitute malicious code via a branch named after the pinned SHA. A proof-of-concept plugin silently spread to over 26,000 agents before being removed, while a parallel campaign called SkillJacking hijacked 925 active skills and impacted 134,000 agents. Anthropic and OpenAI issued patches, but GitHub Copilot had not released a fix at the time of disclosure, and Google chose to deprecate Gemini CLI entirely rather than patch it. The incident highlights that AI coding agent plugin marketplaces have inherited the same supply chain attack risks as traditional package managers, with automatic background updates making exploitation especially stealthy.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in