helpnetsecurity.com web signal

Plugin4Shell Zero-Click RCE Hits Claude Code, Codex, Copilot and Gemini CLI Plugin Systems

Summary

AIR researchers disclosed Plugin4Shell on Sept 18, a zero-click RCE that lets attackers swap malicious plugin code past SHA-pinning checks in Claude Code, OpenAI Codex, GitHub Copilot and Gemini CLI. Anthropic patched in Claude Code 2.1.179 and OpenAI in Codex 0.146.0; Google deprecated Gemini CLI without patching and Microsoft did not ship a Copilot fix. The flaw exploits Git checkout resolving a branch name that matches a commit hash, bypassing the pin while the agent reports a clean install.