AI coding agents’ 0-click RCE flaw could hand attackers keys to the kingdom

← Back to the feed

AI coding agents’ 0-click RCE flaw could hand attackers keys to the kingdom

The Register · 2 weeks ago

Researchers have disclosed “Plugin4Shell”, a zero-click remote-code-execution vulnerability affecting major AI coding agents, including Claude Code, Codex, Gemini CLI and Microsoft Copilot. The flaw targets trusted plugin marketplaces and could let attackers run malicious code with access to any data or systems reachable by the coding agent, creating a significant software supply-chain risk.

The vulnerability bypasses safeguards intended to pin plugins to immutable commit hashes, allowing a repository’s content to be replaced while the pinned reference appears unchanged. Anthropic and OpenAI have issued fixes, while Google will not patch its deprecated Gemini CLI and Microsoft Copilot remains disputed as vulnerable; automatic plugin updates can make exploitation require no user action.

  • Plugin4Shell enables zero-click attacks against major AI coding agents.
  • Attackers could access data and systems available to compromised agents.
  • Claude Code and Codex are patched; Gemini CLI and Copilot remain concerns.

AI Research Science Technology

Read the full article at the source →