On September 18th, security researchers publicly disclosed a vulnerability with an ominous, familiar-sounding name: Plugin4Shell. It is a zero-click remote code execution flaw that hits four of the most widely used AI coding agents on the market — Claude Code, OpenAI Codex, GitHub Copilot, and Google’s Gemini CLI — and it does something that should worry anyone who has come to rely on these tools for daily work. It defeats the exact safeguard that was supposed to make installing third-party plugins safe in the first place.
A Trick as Old as Git, Aimed at a New Kind of Trust
The vulnerability was discovered by the research lab AIR Security, which found working proof-of-concept attacks back in May 2026 and coordinated disclosure with all four affected vendors the following month. The bug itself was made public on September 18, and it exploits something subtle about how these coding agents verify the plugins and skills they pull from marketplaces.
Each of these agents lets developers install third-party plugins, and each one locks a plugin to a specific, reviewed version using a Git commit hash — a 40-character string that is supposed to guarantee the code you get is the exact code that was audited. The problem, as AIR Security researchers put it, is that Git “can interpret a requested commit SHA as a branch name.” In Claude Code, Codex, and GitHub Copilot, the agents run a git checkout against the pinned hash but never confirm that the checkout actually retrieved that commit. An attacker who controls the plugin’s repository can create a branch named identically to the pinned SHA and point it at malicious code. Git, given the choice, resolves to the branch rather than the commit — and the agent installs the swapped code while still reporting the version as “locked.” Gemini CLI has a related but distinct flaw: it fetches the pinned commit but then checks out FETCH_HEAD, which can be hijacked the same way if the attacker names a branch FETCH_HEAD.
Four Agents, Two Patches, and a Tool Google Won’t Fix
What makes Plugin4Shell more than an academic curiosity is the uneven response across the industry. Anthropic patched Claude Code in version 2.1.179 back in June, and OpenAI shipped a fix for Codex in version 0.146.0 in August — both ahead of the public disclosure. GitHub Copilot has not received a patch, and Microsoft has not given a timeline for one. Google’s response is the most striking: the company has confirmed it will not fix Gemini CLI at all, instead pointing users toward Antigravity, its newer agentic coding product, effectively retiring the vulnerable tool rather than repairing it.
There is a meaningful mitigation buried in the details: GitHub itself blocks branch names that look like commit hashes, so plugins hosted directly on GitHub are already protected against this specific trick. The real exposure sits with plugins pulled from Bitbucket, self-hosted GitLab instances, or private Git servers that don’t enforce the same naming restriction — which describes a meaningful slice of the enterprise plugin ecosystem that has grown up around these agents in the past year.
How the Exploit Actually Unfolds
The attack chain described by researchers is quietly patient, which is part of what makes it dangerous. An attacker publishes a plugin that behaves exactly as advertised and passes marketplace review at some initial commit. Developers install it, pin it, and move on. Later, the attacker ships a routine, still-benign update and gets it re-pinned. Only then does the attacker create a branch named after that new commit hash and quietly redirect it to malicious code, while leaving the repository’s default branch pointed there too. The next time the agent’s background auto-updater checks for the pinned version — a default, largely invisible behavior in all four tools — the checkout resolves to the poisoned branch, and the malicious code runs with whatever access the user has already granted the agent: reading files, touching credentials, or reaching into connected systems. No click, no approval dialog, no warning.
That is the detail security teams keep emphasizing: doing everything right — reviewing a plugin before installing it, pinning it to a specific commit — does not protect you, because the entire point of the exploit is that the pin itself can be silently reassigned underneath you.
The Bigger Problem: Autonomous Agents Trusting by Default
Plugin4Shell lands at an awkward moment for the AI coding industry, which has spent 2026 racing to make these agents more autonomous — running longer unsupervised sessions, executing terminal commands, and managing their own plugin ecosystems with less human oversight at every step. AIR Security has noted that this is not an isolated incident either: the same research lab previously documented roughly 925 compromised skills already in circulation, collectively affecting some 134,000 agents, a sign that the plugin and skill marketplaces built around AI coding tools have grown faster than the security review processes meant to police them.
The core tension is structural rather than incidental: these agents are designed to fetch and execute third-party code automatically, in the background, because that convenience is exactly what makes them useful for fast-moving development teams. Every layer of that convenience — auto-updates, implicit trust in version pins, minimal user confirmation — is also a potential seam for exactly this kind of attack.
What Developers Can Do Right Now
For Claude Code and Codex users, the fix is straightforward: confirm you are running at least version 2.1.179 or 0.146.0 respectively, since updating closes the hole entirely. GitHub Copilot and Gemini CLI users have fewer good options until Microsoft ships a patch or teams migrate off Gemini CLI toward Antigravity as Google is recommending. In the meantime, security researchers are advising a few concrete habits: disable background auto-updates for installed plugins where the tool allows it, favor plugins hosted on GitHub over other Git hosts given the platform’s built-in protection against hash-like branch names, and treat any coding agent’s plugin marketplace with the same scrutiny normally reserved for open-source dependencies in a production codebase — because, as Plugin4Shell makes clear, that is functionally what they have become.
No CVE identifier had been assigned to Plugin4Shell as of publication, and researchers say they have not yet seen evidence of the technique being used in the wild. That is a narrow window that is unlikely to stay open for long, particularly for the two agents whose vendors have already said, in effect, that a fix isn’t coming.