Plugin4Shell flaw hits Claude Code, Codex, Gemini CLI and Copilot
Researchers disclosed a vulnerability class called Plugin4Shell affecting four major AI coding agents: Claude Code, Codex, Gemini CLI and Copilot. Broken SHA-pinning verification lets attackers swap an approved plugin for malicious code, and default auto-update runs it silently with full agent-level access to files, credentials and CI pipelines.
- Flaw affects Claude Code, Codex, Gemini CLI and Copilot
- SHA-pinning verification fails to guarantee code immutability
- Auto-update runs swapped plugins with no user prompt
- Attackers gain access to files, credentials and cloud accounts
Read next
Security