{"id":774451,"date":"2026-09-18T07:02:14","date_gmt":"2026-09-18T07:02:14","guid":{"rendered":"https:\/\/www.newsbeep.com\/uk\/774451\/"},"modified":"2026-09-18T07:02:14","modified_gmt":"2026-09-18T07:02:14","slug":"ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/uk\/774451\/","title":{"rendered":"AI coding agents&#8217; 0-click RCE flaw could hand attackers keys to the kingdom"},"content":{"rendered":"<p>                    <a data-tag=\"security\" href=\"https:\/\/www.theregister.com\/tag\/security\" class=\"lab-article-section-link\" rel=\"nofollow noopener\" target=\"_blank\"><\/p>\n<p style=\"\" class=\" lab-article-section lab-article-section-top \">\n                    security\n                <\/p>\n<p>                    <\/a><\/p>\n<p class=\"subtitle below\" style=\"\">\n        Plugin4Shell attack affects all the major coding agents, researchers say\n    <\/p>\n<p>A zero-click vulnerability that allows remote code execution affects all of the major AI coding agents &#8211; Anthropic\u2019s Claude Code, OpenAI\u2019s Codex, Google&#8217;s Gemini CLI, Microsoft\u2019s Copilot, and Microsoft-owned GitHub Copilot &#8211; and could give attackers full access to every asset and piece of data that the agent can reach, researchers say.<\/p>\n<p>The exploit, dubbed \u201cPlugin4Shell,\u201d is a \u201cfirst-of-its-kind AI supply-chain attack,\u201d according to threat hunters at Air, a security startup focused on protecting enterprise AI agents.<\/p>\n<p>Instead of targeting the model or agent, Plugin4Shell attacks trusted marketplaces that host plugins for major coding agents. Such attacks could therefore reach millions of users and machines, the researchers said.<\/p>\n<p>Almost <a href=\"https:\/\/news.microsoft.com\/ai-in-action\/\" target=\"_blank\" rel=\"nofollow noopener\">90 percent<\/a>\u00a0of Fortune 500 companies use Copilot, according to Microsoft, which also happens to be one of the two that didn\u2019t ship a patch for the flaw.<\/p>\n<p>\u201cThe fix has to ship in the agent, and updating is the only complete mitigation where one exists,\u201d Air researchers Or Nevo, Dor Granat, and Niv Hoffman <a href=\"https:\/\/www.air.security\/blog-posts\/plugin4shell\" target=\"_blank\" rel=\"nofollow noopener\">said<\/a> in a Thursday report.<\/p>\n<p>The Air team reported the security issue to all four vendors in June, and both Anthropic and OpenAI patched it in Claude Code 2.1.179 and Codex 0.146.0, respectively.<\/p>\n<p>Google has <a href=\"https:\/\/developers.googleblog.com\/an-important-update-transitioning-gemini-cli-to-antigravity-cli\/\" target=\"_blank\" rel=\"nofollow noopener\">deprecated the Gemini CLI<\/a>, and therefore told Air it will not patch, so every install remains vulnerable. Google does, however, suggest users migrate to its newer Antigravity agentic development environment, which is protected from this attack.<\/p>\n<p>Microsoft didn\u2019t fix the flaw in Copilot. However, a GitHub spokesperson told us the Plugin4Shell attacks do not affect GitHub.<\/p>\n<p>\u201cTo prevent abuse of SHAs, GitHub does not allow users to create branch or tag names that resemble commit SHAs,\u201d the spokesperson said. \u201cThis mitigation ensures the reported vulnerability cannot be exploited on GitHub.\u201d<\/p>\n<p>The Air researchers said that the GitHub mitigation isn\u2019t sufficient to defeat Plugin4Shell attacks. This is \u201cbecause marketplaces can also be hosted in other platforms such as Bitbucket,\u201d the team told The Register.\u00a0<\/p>\n<p>\u201cMicrosoft Copilot is also still vulnerable because it supports marketplaces from such platforms as well, which exposes it to the vulnerability,\u201d the researchers added. \u201cAir also reported the same to Microsoft (since June), but unfortunately due [to] the amount of disclosure volume they\u2019re currently getting we didn\u2019t get a response from them.\u201d<\/p>\n<p>Redmond did not immediately respond to The Register\u2019s request for comment.<\/p>\n<p>The security hole sits in how agents enforce marketplaces\u2019 SHA-pinning mechanism, which locks agent plugins and skills to a specific, immutable commit hash instead of a mutable reference like a version tag or branch name.<\/p>\n<p>This aims to prevent supply chain attacks: If a public skill repository is compromised, your AI agent will continue running the same, audited code hash it used when you pinned it instead of automatically pulling new, malicious payloads.<\/p>\n<p>The researchers describe the vulnerability as a \u201cplugin SHA-pinning bypass.\u201d<\/p>\n<p>\u201cThe agent checks out the exact commit the marketplace pinned but never verifies it landed there, so an attacker who controls the plugin&#8217;s repo makes the checkout resolve to malicious code while the pin still looks honored,&#8221; Nevo, Granat, and Hoffman wrote. \u201cThe result is zero-click remote code execution.\u201d<\/p>\n<p>Agents\u2019 plugin auto-update feature makes this a zero-click attack. When a pinned commit is swapped upstream, the agent\u2019s plugin gets replaced with a malicious version, and both Claude and Codex automatically update installed plugins by default.<\/p>\n<p>The researchers say an attacker could abuse this flaw in two ways. In one scenario, the attacker submits a benign plugin to a trusted marketplace, the plugin passes review, and then the attacker later replaces the benign content with malicious code.<\/p>\n<p>The second attack involves hijacking a legitimate author&#8217;s repository and then pushing the malicious version onto every agent that has it installed &#8211; essentially bypassing the SHA pinning safety mechanism that exists to stop this type of supply chain attack. The team demonstrates this type of takeover in their earlier <a href=\"https:\/\/vimeo.com\/1206553501?fl=pl&amp;fe=sh\" rel=\"nofollow noopener\" target=\"_blank\">SkillJacking<\/a> and <a href=\"https:\/\/vimeo.com\/1214324682?fl=pl&amp;fe=sh\" rel=\"nofollow noopener\" target=\"_blank\">RepoJacking<\/a> proof-of-concept attacks.\u00a0<\/p>\n<p>\u201cTogether, the chain is proven end to end &#8211; takeovers happen at scale, and Plugin4Shell defeats the mechanism built to contain them,\u201d the researchers wrote. \u00ae<\/p>\n","protected":false},"excerpt":{"rendered":"security Plugin4Shell attack affects all the major coding agents, researchers say A zero-click vulnerability that allows remote code&hellip;\n","protected":false},"author":2,"featured_media":774452,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[554,733,4308,86,56,54,55],"class_list":["post-774451","post","type-post","status-publish","format-standard","has-post-thumbnail","category-artificial-intelligence","tag-ai","tag-artificial-intelligence","tag-artificialintelligence","tag-technology","tag-uk","tag-united-kingdom","tag-unitedkingdom"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/774451","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/comments?post=774451"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/774451\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media\/774452"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media?parent=774451"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/categories?post=774451"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/tags?post=774451"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}