One flaw hit Claude Code, Codex, Copilot and Gemini CLI

Illustration for the Plugin4Shell coding agent vulnerability story

Four AI coding agents built by four different companies all shipped the same plugin verification failure, and security lab AIR published it as Plugin4Shell on 17 September 2026. Two of the four are patched, one has no fix, and one will never get one.

The flaw matters because of what it defeats: the SHA pinning that plugin marketplaces use to guarantee that the code an agent installs is the code that was reviewed. It is also zero click, because the agents update installed plugins on their own. For anyone running an agent against a real repository, the exposure is the agent’s full permission surface.

How the attack works

The agent requests the exact commit a marketplace pinned. According to AIR’s disclosure, “the agent checks out the exact commit the marketplace pinned but never verifies it landed there.” Nothing confirms that the working tree matches the pin.

For Claude Code, Codex and Copilot, an attacker who controls a plugin repository creates a branch whose name is the exact 40 character hexadecimal hash and makes it the repository default. Git resolves the reference name ahead of the commit object, so the malicious branch is what lands, while the agent reports a successful install against the expected SHA. Gemini CLI falls to a different variant, where the repository default branch is itself named FETCH_HEAD. AIR notes that GitHub rejects a 40 character hexadecimal branch name outright, so the first version requires a host that permits them.

It is zero click because, in AIR’s words, “Agents update installed plugins in the background - in Claude Code and Codex this is the default.”

Where each vendor stands

Anthropic patched Claude Code in version 2.1.179 and OpenAI patched Codex in version 0.146.0. AIR found the flaw in May 2026 and disclosed it to vendors in June 2026.

Microsoft has shipped no fix for Copilot, so those users have no patch. Google deprecated Gemini CLI and will not patch it, advising users to migrate to Antigravity. In AIR’s words, “every install stays vulnerable for good.”

The repeated assumption

AIR’s framing is that this is not four bugs. It is one design error reproduced independently across the industry, in a layer that every vendor built at speed over roughly the same period.

What is unresolved is Copilot. It is the only one of the four agents where a patch is both technically possible and still absent.

Sources

ANOTHER News is published by ANOTHER, an AI-native content agency. Daily coverage also runs on Instagram.