All Insights

Plugin4Shell: The AI Coding Tool Vulnerability Two Vendors Chose Not to Fix

CivSafe Team·September 19, 2026·6 min read

There's a zero-click remote code execution vulnerability in four of the most popular AI coding tools on the market right now.

If you have a plugin installed from a trusted, reviewed marketplace — following the security model exactly as intended — an attacker who controls that plugin's repository can swap in malicious code the next time your agent auto-updates. No phishing. No user action. No warning. The plugin still shows as the trusted, pinned version you installed.

AIR Security researchers Or Nevo, Dor Granat, and Niv Hoffman disclosed this on September 17. They named it Plugin4Shell. They found it in Claude Code, OpenAI Codex, GitHub Copilot, and Google Gemini CLI.

Two of those vendors have patched. Two have not — and one of them told users they never will.

How It Works

AI coding agents use SHA pinning to lock plugins to specific versions. The idea: when a marketplace reviews a plugin and approves it, they record the exact Git commit hash (SHA) of the code they reviewed. Your agent is then supposed to install only that exact commit — not a newer version, not anything else.

Plugin4Shell breaks this assumption in one missing step. The agents request the pinned commit, but they never verify that the checked-out code actually matches it.

That gap is the vulnerability. Git resolves references — branch names, tags, commit hashes — in a specific order. If you create a branch whose name is the same 40-character string as the approved commit SHA, git will resolve the branch before the commit. The agent thinks it's installing the approved code. It installs the attacker's branch instead.

The researchers described it simply: "The agent checks out the exact commit the marketplace pinned but never verifies it landed there, so an attacker who controls the plugin's repo makes the checkout resolve to malicious code while the pin still looks honored."

No collision attack. No cryptographic break. Just a missing check.

The "zero-click" part comes from how modern agents manage updates. When a marketplace bumps a pinned SHA, your agent automatically pulls the new version in the background. If an attacker has staged their malicious branch before that point, the swap happens while you're working on something else. Your IDE looks normal. Your plugin looks installed and approved. The malicious code is running.

There are two ways in. The first: submit a legitimate plugin, pass review, get the commit pinned, then replace the code. The second: compromise a legitimate plugin author's repository and push malicious code to everyone who already has their plugin installed.

Who Is Affected

GitHub Copilot (Microsoft) — unpatched. This is the tool that matters most for small orgs. GitHub Copilot is bundled with Teams and Enterprise GitHub licenses, which means anyone using GitHub for code hosting may have Copilot extensions installed without actively choosing to. Microsoft's official position is that SHA restrictions provide sufficient mitigation. The researchers disagree, and the vulnerability remains open.

Google Gemini CLI — will not be patched. Google is retiring Gemini CLI. They've told users it won't receive a fix. If you adopted Gemini CLI when it launched and have plugins installed, you are permanently exposed unless you switch to something else.

Claude Code — patched in version 2.1.179. Update immediately if you haven't.

OpenAI Codex — patched in version 0.146.0. Update immediately if you haven't.

AIR found the vulnerability in June 2026 and followed a standard 90-day responsible disclosure window before going public. All four vendors had three months to prepare a response. Two did.

Why the "Trusted Marketplace" Model Is the Problem

The conventional advice for staying safe with AI coding tools is: only install plugins from official marketplaces, look for the "reviewed" badge, stick to established publishers.

Plugin4Shell means none of that protects you.

The review happened. The SHA was pinned. The publisher is legitimate. The attack exploits the space between "the code that was approved" and "the code your agent actually ran" — a gap that exists because agents assumed the approval process handled a verification step it never did.

This is what makes supply chain attacks particularly nasty. You did everything right. The process worked exactly as designed. The vulnerability is in the trust model itself, not in your choices.

For small teams, this matters more than it does for organizations with dedicated security monitoring. Larger companies run endpoint detection on developer machines that flags unusual process behavior, network calls to unexpected destinations, credential access from new processes. Smaller teams typically don't have that. When a plugin silently exfiltrates your AWS credentials or installs a persistent backdoor during an auto-update at 2am, you may not find out for weeks.

What To Do Right Now

Audit your installed plugins. Go through every AI coding tool your team uses and list every plugin and extension installed. Do you actually use all of them? Can you identify the publisher? Remove anything you don't actively need. A plugin you forgot about is still running.

Update immediately if you use Claude Code or Codex. Claude Code 2.1.179+ and Codex 0.146.0+ are patched. This is a straightforward update — do it today.

If you use GitHub Copilot, be extremely conservative about plugins right now. Microsoft disputes whether their SHA restrictions are sufficient, and researchers say they're not. Until there's a clear patch, avoid installing new Copilot extensions and review what's already installed. If you can disable auto-updates for extensions, do it.

If you use Gemini CLI, it's time to move. Google has stated there will be no fix. The product is being retired. If you have plugins installed on a Gemini CLI instance, treat that environment as potentially compromised until you migrate away.

Treat your developer machines like what they are: high-value targets. Coding agents run with your full user permissions. They have access to cloud credentials, API keys, database connections, SSH keys, and production secrets stored in your environment. An RCE on a developer machine isn't just that developer's problem — it's your company's AWS account, your client database, your source code. The blast radius is large.

Watch for plugin updates from unfamiliar repos. If a plugin your team installed is suddenly updating frequently from a repository that wasn't what you remember, that's worth investigating.

The Bigger Picture

Plugin4Shell is the first documented supply chain vulnerability in the AI coding agent ecosystem. It will not be the last. The plugin model creates trusted distribution channels that are now understood attack surfaces, and the market has not yet developed the verification infrastructure to make those channels genuinely safe.

AIR's research is worth reading in full if your team uses any of the affected tools. The summary from the researchers is useful: this isn't an exotic attack. It's one missing verification check, exploitable by anyone with commit access to a plugin you have installed.

We help small teams think through their AI tooling stack from a security perspective — what's installed, what access it has, what the realistic attack paths look like. If you want that conversation, reach out.

In the meantime: update what's patchable, remove what you don't need, and don't trust auto-updates to deliver what they say they're delivering.

CivSafe — Strategic Innovation. Community Impact.