DEV Community

Cover image for Plugin4Shell Vulnerability Enables Zero-Click RCE in Leading AI Coding Agents
BeyondMachines for BeyondMachines

Posted on Originally published at beyondmachines.net

Plugin4Shell Vulnerability Enables Zero-Click RCE in Leading AI Coding Agents

Summary

The Plugin4Shell vulnerability enables zero-click remote code execution in AI coding agents like Claude Code and GitHub Copilot by bypassing SHA-pinning integrity checks. Attackers can swap verified plugin code for malicious versions, gaining full control over developer machines and sensitive corporate data.

Take Action:

If you use Claude Code or Codex, update them now (Claude Code 2.1.179 or later, Codex 0.146.0 or later). If you use GitHub Copilot or the consumer Gemini CLI, there is no patch for this flaw, so if possible turn off automatic background plugin updates, remove any plugins you don't truly need, and move off Gemini CLI to Antigravity.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)