Plugin4Shell: one git trick bypassed safety locks on four AI coding agents
Air Security disclosed Plugin4Shell, a zero-click RCE flaw in Claude Code, Codex, GitHub Copilot and Gemini CLI. The agents never verify the pinned commit they receive, and git silently prefers a branch named like a hash. Anthropic and OpenAI patched; Microsoft and Google did not.
- Flaw affects Claude Code, Codex, Copilot and Gemini CLI
- Anthropic fixed it in 2.1.179, OpenAI in Codex 0.146.0
- Microsoft shipped no fix; Google won't patch Gemini CLI
- Fix is one line: verify the working tree matches the pin
Read next
Security