Plugin4Shell – Zero Click RCE Vulnerability found in top four coding agents (www.air.security)

🤖 AI Summary
A critical security vulnerability known as Plugin4Shell has been discovered in major AI coding agents, including Claude Code, OpenAI Codex, GitHub Copilot, and Gemini CLI. This zero-click remote code execution (RCE) issue arises from a failure in the SHA-pinning mechanism designed to secure plugin updates. Malicious actors can exploit this flaw without requiring user interaction, simply by replacing a previously benign plugin with harmful code under the same SHA reference. This allows attackers complete access to sensitive enterprise data and systems without any direct actions from users—essentially leveraging trust in community marketplace plugins. The significance of Plugin4Shell lies in its position as the first major supply chain vulnerability in the AI agent ecosystem, revealing a widespread design flaw in how these agents manage plugin security. This vulnerability affects all users of the affected coding agents who trust and install plugins from community marketplaces, underscoring the need for robust security measures in plugin distribution. Although immediate patches have been implemented for some platforms, GitHub Copilot remains vulnerable due to the lack of a fix, and Google has deprecated Gemini CLI without a patch, leaving users exposed. The incident highlights the critical necessity for stringent security protocols in plugin management to safeguard businesses from potential exploitation.
Loading comments...
loading comments...