AIR Security researchers describe Plugin4Shell, a zero-click remote code execution flaw affecting Claude Code, Codex, Copilot, and Gemini, in which a trusted plugin is silently swapped for a malicious one and auto-installed past the agent’s SHA pinning, a supply-chain weakness they say no plugin marketplace can fix and that users must address by updating their agent.
Plugin4Shell: Zero-Click RCE Found in Top Four Coding Agents
AIR Security researchers describe Plugin4Shell, a zero-click remote code execution flaw affecting Claude Code, Codex, Copilot, and Gemini, in which a trusted plugin is silently swapped for a malicious one and auto-installed past the agent's SHA pinning, a supply-chain weakness they say no plugin marketplace can fix and that users must address by updating their agent.
Source: Air