Hacker News
Plugin4Shell – Zero Click RCE Vulnerability found in top four coding agents
Plugin4Shell is a supply-chain flaw that bypasses SHA-pinning in AI agent marketplaces, allowing an attacker to replace a pinned commit with malicious code during background plugin updates. The vulnerability gives zero-click remote code execution on agents such as Claude Code, Codex, GitHub Copilot, and Gemini CLI, compromising the host machine and all data the agent can access. The flaw is present in every major coding agent that installs plugins from a marketplace, rendering the usual pinning safeguard ineffective.