2 hrs ago
Plugin4Shell Hits Four Major AI Coding Assistants; Two Unpatched
Researchers found one security flaw affecting four popular AI coding assistants.
They named the flaw Plugin4Shell.
A bad plugin update could run harmful computer code without the developer clicking anything.
The attack tricks the tool into loading dangerous code instead of the approved plugin version.
It does this by using a branch name that looks like the approved code’s fingerprint.
Anthropic fixed the problem in Claude Code.
OpenAI fixed it in Codex.
Google’s Gemini CLI is still reported to be vulnerable.
Researchers also say GitHub’s Copilot mitigation may not solve the whole problem.
Plugin4Shell affects Claude Code, OpenAI Codex, GitHub Copilot and Gemini CLI.
The flaw can execute malicious plugin code on a developer’s machine without user approval or action.
Attackers exploit version-control name resolution to bypass plugins’ supposedly fixed commit-hash protections.
Anthropic and OpenAI have released fixes for Claude Code and Codex, respectively.
Google’s Gemini CLI remains exposed, while researchers dispute how fully GitHub’s Copilot mitigation works.
- Who
- Researchers identified Plugin4Shell in Claude Code, OpenAI Codex, GitHub Copilot and Gemini CLI.
- What
- A zero-click supply-chain vulnerability can cause a malicious plugin update to execute attacker-controlled code.
- Where
- On developers’ machines running the affected AI coding assistants.
- When
- Why
- The flaw exploits how plugins pinned to approved commit hashes are resolved, allowing malicious code to appear authorized.
Researchers’ assessment
Companies’ responses
GitHub Copilot mitigation
Researchers’ assessment
Researchers dispute whether GitHub’s mitigation fully addresses the vulnerability and say the issue remains unresolved.
Companies’ responses
GitHub says a mitigation exists for GitHub Copilot.
Overall patch status
Researchers’ assessment
Researchers’ account indicates that two of the four tools remain exposed or unresolved, meaning users should not assume every affected tool is protected.
Companies’ responses
Anthropic and OpenAI have shipped fixes for Claude Code and Codex, while GitHub reports a Copilot mitigation.
Key facts
- Vulnerability
- Plugin4Shell
- Affected tools
- Anthropic’s Claude Code, OpenAI Codex, GitHub Copilot and Google’s Gemini CLI
- Attack type
- Zero-click plugin supply-chain attack
- Exploitation method
- A malicious branch name matching a 40-character commit fingerprint can be selected instead of the approved code.
- Patched products
- Claude Code and Codex
- Unresolved products
- Gemini CLI is reported as still exposed; Copilot’s mitigation is disputed by researchers.
- Potential access
- Compromised coding assistants may reach source code, credentials and command-execution capabilities on a developer’s machine.










