A Zero-Click RCE Flaw in AI Coding Agents Could Have Exposed Enterprise Systems
9 Articles
9 Articles
A zero-click RCE flaw in AI coding agents could have exposed enterprise systems
Popular AI coding agents such as OpenAI’s Codex, Anthropic’s Claude Code, Google’s Gemini CLI, and Microsoft-owned GitHub Copilot were vulnerable to a zero-click attack that enabled attackers to execute malicious code, even without developer interaction, by swapping a trusted plugin from an online marketplace for a malicious one, potentially giving them a foothold in enterprise development environments. Researchers at cybersecurity startup AIR f…
Plugin4Shell exposes major AI coding agents to zero-click RCE
Researchers at Air say the Plugin4Shell flaw affects Claude Code, OpenAI Codex, Gemini CLI, Microsoft Copilot, and potentially GitHub Copilot via plugin marketplaces. The issue bypasses SHA pinning by making agents fetch malicious code while still...
Plugin4Shell Bypasses SHA Pinning Across All Four Major AI Coding Agents
The security of the AI agent ecosystem has long relied on a simple, foundational assumption: if you pin a specific version of a plugin using a cryptographic hash, you are guaranteed to run that exact code. Plugin4Shell proves that this assumption is fundamentally broken. Discovered by the AIR Security research lab, Plugin4Shell is the first […]
Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched
Four major AI coding agents, Claude Code, Codex, GitHub Copilot and Gemini CLI, all share the same zero-click RCE vulnerability, one that could give an attacker the same reach into a company’s systems and data as the employee running the agent, according to AIR. “It is the first supply chain vulnerability of the AI agent ecosystem,” the researchers said. “Anyone running a major coding agent that installs plugins from a marketplace is exposed. Th…
A zero-click vulnerability named Plugin4Shell could allow attackers to run remote code via plugin marketplaces used by major coding agents with AI. Anthropic and OpenAI have already published corrections, while Google left Gemini CLI and Microsoft Copilot continues to be questioned.
Coverage Details
Bias Distribution
- 67% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium










