DigiNews

Tech Watch by Johan Denoyer

← Back to articles

Plugin4Shell - Zero Click RCE Vulnerability found in top 4 most popular coding agents, millions of agents affected

Quality: 8/10 Relevance: 9/10

Summary

Air Security reports Plugin4Shell, a zero-click remote code execution vulnerability affecting Claude Code, Codex, Copilot, and Gemini CLI via plugin SHA pinning bypass. The attack enables automatic background replacement of trusted plugins with malicious code without user interaction, highlighting AI agent supply-chain risks. Patches have been released for Claude Code and Codex; Copilot has not shipped a fix, and Gemini CLI is deprecated; mitigation focuses on updating agents and pinning to reviewed commits.

🚀 Service construit par Johan Denoyer