Code that was supposed to be "approved" was secretly replaced
On September 17th, three researchers from AI security company AIR (Or Nevo, Dor Granat, and Niv Hoffman) disclosed a vulnerability they named "Plugin4Shell." This is a zero-click remote code execution (RCE) vulnerability present in all four of the most widely used AI coding agents: Claude Code, OpenAI Codex, GitHub Copilot, and Gemini CLI. Without requiring any user clicks or authorizations, an attacker with control of the plugin repository can secretly replace already approved code. AIR explains that this is the first vulnerability of its kind targeting the AI agent supply chain.
All four companies overlooked the promise of SHA fixation
The technical core is simple. Many plugin marketplaces have a mechanism to fix reviewed plugins to a specific Git commit hash (SHA). This is a subtle but important safety mechanism to ensure that "only approved plugins work." However, according to AIR's investigation, none of the Claude Code, Codex, Copilot, or Gemini CLI verified whether the commits actually checked out after installation truly matched the fixed SHA recorded in the marketplace. An attacker could bypass this single-line comparison check by using the SHA string itself as the branch name. The fact that all four companies independently overlooked the same single-line check suggests that this is not a vendor implementation error, but a common structural problem in how the entire industry has designed AI agent plugin mechanisms.
Plugins have "the same privileges as the developer"
What cannot be overlooked is why this vulnerability is serious. Plugins, skills, and extensions for AI agents often inherit the same privileges as the developer running them. Everything within the agent's reach—local source code, cloud credentials, SSH keys, internal repositories, production systems, and sensitive information—can be targeted. AIR positions this vulnerability as the first supply chain vulnerability in the AI agent ecosystem, meaning that "an attacker can infiltrate the system with the same perspective as the developer, even though the agent itself is not performing any operations."
Varying Responses Among the Four Companies
What is particularly interesting this time is the difference in the speed and attitude of each company's response after disclosure. Anthropic and OpenAI had already distributed corrected versions several months before the public disclosure (AIR discovered it in May, and notified each company in June), with Claude Code 2.1.179 and Codex 0.146.0, respectively. On the other hand, Microsoft had not yet released a patch for GitHub Copilot as of September 21st. GitHub explains that "the platform blocks the use of strings like SHA as branch names and tag names," but AIR points out that this defense may be bypassed if using Bitbucket or a marketplace on a self-hosted Git server. Google has indicated its intention to discontinue the consumer version of Gemini CLI altogether, urging users to migrate to its successor, "Antigravity," instead of providing a fix. The differing responses to the same vulnerability—some companies quickly fix it, others partially delegate defense to the platform, and still others discontinue the product altogether—reflect the differences in each company's security operational structure.
No Actual Exploitation Confirmed
One reassuring point is that AIR states that no evidence of actual exploitation of this vulnerability has been found. A CVE number has not yet been assigned. AIR created proof-of-concept code in May, following a responsible disclosure process with approximately three months' grace period between notification to companies and public release.
What Engineers Should Note
If you are using Claude Code and Codex, the top priority should be updating to versions 2.1.179 and 0.146.0 or later, respectively. If you're using GitHub Copilot, the most practical defense for the time being is to avoid installing plugins from sources other than the GitHub-hosted marketplace and to disable automatic updates for third-party plugins as much as possible. As for Gemini CLI, since Google has stated there are no plans to fix it, you should consider migrating to Antigravity. A more fundamental lesson is that the mechanism of "fixing to a reviewed hash" in AI agent plugin mechanisms can be a safety measure in name only unless you separately verify that the hash is actually properly validated. As a permanent measure for vendors, it is necessary to reliably incorporate a single line of verification after installation that compares the actual HEAD value with the fixed SHA from the marketplace.