Summary
The Plugin4Shell vulnerability enables zero-click remote code execution in AI coding agents like Claude Code and GitHub Copilot by bypassing SHA-pinning integrity checks. Attackers can swap verified plugin code for malicious versions, gaining full control over developer machines and sensitive corporate data.
Take Action:
If you use Claude Code or Codex, update them now (Claude Code 2.1.179 or later, Codex 0.146.0 or later). If you use GitHub Copilot or the consumer Gemini CLI, there is no patch for this flaw, so if possible turn off automatic background plugin updates, remove any plugins you don't truly need, and move off Gemini CLI to Antigravity.
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (0)