AIR Discloses Plugin4Shell Zero-Click RCE in AI Coding Agents
TL;DR
- AIR found working exploits against all four agents in May 2026, disclosed to vendors in June; no CVE was assigned at publication.
- The flaw is identical across all four agents: git resolves a branch named after the pinned SHA, silently replacing the pinned commit with attacker-controlled code.
- Claude Code 2.1.179 and Codex 0.146.0 carry full fixes; Copilot had no patch at disclosure and Gemini CLI was deprecated without one.
Plugin4Shell, disclosed by researchers at AIR and covered this week in Help Net Security, lets an attacker swap malicious code into a pinned plugin on four major AI coding agents without any user action. AIR calls it "the first supply chain vulnerability of the AI agent ecosystem" and reports that "925 skills already in active use had been hijacked," reaching "134,000 agents."
The bug breaks SHA pinning, the mechanism that is supposed to lock a plugin to a specific reviewed commit. AIR found that every one of the four agents "checks out the pinned commit without verifying the checkout landed there." Create a branch whose name matches the plugin's 40-character commit hash, make it the default branch, and git resolves the reference before the commit object, because "git prefers a ref over a commit of the same name." The install reports the expected SHA. The malicious code runs.
"The victim only has to have a plugin installed, from a marketplace they trust, that was reviewed," AIR writes. Zero-click, because "the same git checkout re-runs on background auto-update."
Anthropic shipped a fix in Claude Code 2.1.179 and OpenAI patched Codex in 0.146.0. Microsoft has not released a Copilot fix. Google is not patching Gemini CLI, having deprecated it and pointed users at Antigravity.
AIR researchers Or Nevo, Dor Granat and Niv Hoffman found the bug in May 2026 and disclosed it to vendors the following month.
What others are reporting
-
AIR Security Read →
First-party disclosure from the researchers who found the bug; explains exact git branch-name mechanics, full attack chain through auto-update, and patched version numbers for all four vendors.
A marketplace cannot fully close this. The pin is resolved inside the agent, so only an agent-side fix restores the guarantee.
-
The Hacker News Read →
Provides a vendor-by-vendor patch status table with version numbers and notes GitHub's SHA-like branch name restrictions as a partial mitigation that varies by repository host.
The agents fetch that snapshot but never check that the code they end up with actually matches it.
-
Cyber Security News Read →
Details FETCH_HEAD abuse and branch-name prioritization as the specific git mechanics exploited, and distinguishes residual risk on self-hosted git servers where GitHub's mitigations do not apply.
The flaw allows a malicious plugin update to execute attacker-controlled code without requiring a user to click, approve, or reinstall anything.
-
AiCybr Read →
Most granular vendor remediation breakdown; confirms Gemini CLI users are directed to Antigravity with no patch path and notes GitHub's partial mitigation for Copilot on github.com.
An attacker who controls the relevant plugin repository can cause the client to obtain different code while the marketplace still presents the expected pin.
-
Forkast Read →
Contextualizes Plugin4Shell within AIR's prior supply-chain research, citing LiteLLM and Sentry MCP as precursors; frames this as the first class vulnerability in AI agent distribution.
Plugin4Shell proves that this assumption is fundamentally broken.
-
GBHackers Read →
Covers differential vendor response timelines and highlights that Microsoft had not released a Copilot fix at the time of disclosure, leaving the largest installed base exposed.
Agents must verify the commit that is actually checked out after installation.
Originally reported by helpnetsecurity.com
Read the original article →Original headline: Plugin4Shell Zero-Click RCE Hits Claude Code, Codex, Copilot and Gemini CLI Plugin Systems