Plugin4Shell: zero-click RCE hits Claude Code, Codex, Copilot and Gemini CLI
AIR Security disclosed Plugin4Shell, a flaw that lets attackers silently swap SHA-pinned plugin code in four popular AI coding agents. Anthropic and OpenAI have shipped patches, Microsoft has not fixed Copilot, and Google is discontinuing Gemini CLI instead.
- Flaw affects Claude Code, Codex, GitHub Copilot and Gemini CLI
- Anthropic fixed it in 2.1.179, OpenAI in 0.146.0
- Microsoft has no patch; Google is retiring Gemini CLI
- Attack requires a git host allowing hex-named branches
Read next
Security