A single git trick beat the safety lock on four AI coding agents

https://media.thenextweb.com/2026/09/backlit-keyboard-two-monitors-source-code-dark-room.jpg

The AI industry already knew attackers could poison plugin marketplaces. Its answer was to lock every plugin to one reviewed version of its code. That lock is what just broke.

Researchers at Air Security published a vulnerability on Thursday that they call Plugin4Shell. It affects the four most widely used AI coding agents. Those are Anthropic’s Claude Code, OpenAI’s Codex, GitHub Copilot and Google’s Gemini CLI. Or Nevo, Dor Granat and Niv Hoffman call it zero-click remote code execution. The attacker needs no action at all from the victim. Jessica Lyons first reported it for The Register.

Anthropic fixed it in Claude Code 2.1.179 and OpenAI in Codex 0.146.0. Microsoft has shipped no fix for Copilot. Google will not fix the Gemini CLI, because it is retiring it.

What Plugin4Shell actually does

Coding agents install add-ons from marketplaces. To keep those add-ons safe, a marketplace pins each one...

Copyright of this story solely belongs to thenextweb.com. To see the full text click HERE

Read more