You pinned the plugin to an exact commit SHA. Forty hex characters. Immutable. That's the whole point of pinning — the code can't change under you.
Except it can. And for a few weeks this month, across four of the most popular AI coding agents, it did — with zero clicks from you.
On 17 September, AIR Security researchers disclosed Plugin4Shell: a flaw in how Claude Code, OpenAI Codex, GitHub Copilot and Gemini CLI install SHA-pinned plugins from marketplaces. Whoever controls a plugin's repository could swap the already-approved code for something else, and the agent would run it while cheerfully reporting the expected SHA as installed.
Let me walk through why, because the mechanism is almost insultingly simple — and it's a lesson that applies far beyond these four tools.
"Pinned to a SHA" was a lie the tools told themselves
Here's what the agents did on install:
- Ask Git to check out the pinned commit
a1b2c3…(40 chars). - Report success: "installed
a1b2c3…". ✅ - Run the plugin.
What they didn't do: verify that the working tree they just checked out actually corresponds to that SHA.
That gap is everything. Git has reference-name ambiguity: if a repository contains a branch whose name is the same 40-character string as the commit hash, git checkout a1b2c3… can resolve to the branch ref, not the commit object. Git happily hands you the branch's tip. The tool prints the SHA it asked for, not the one it got.
The pin was checked as a request, never as a result. "I asked for this commit" is not "I am running this commit." That one missing verification is the whole CVE-that-isn't-even-a-CVE-yet.
So a plugin author (or anyone who compromises the repo) pushes a branch named after the pinned hash, points it at malicious code, and every agent that "updates" to the pinned version pulls attacker code — no prompt, no diff, no click. Auto-update did the rest.
Who's patched (check this now)
As of disclosure:
| Agent | Status |
|---|---|
| Claude Code | Patched — 2.1.179 |
| OpenAI Codex | Patched — 0.146.0 |
| GitHub Copilot | No fix shipped |
| Gemini CLI | Retired without a fix |
If you're on Claude Code or Codex, check your version right now — being pinned to a fixed build is the fix. If you're on Copilot or Gemini CLI plugins, treat any auto-updating third-party plugin as untrusted until you know more.
No CVE and no real-world attack were on record at disclosure. That's luck, not safety.
The bigger lesson: your agent's plugin store is the new npm
We spent a decade learning that a dependency you didn't audit is code you didn't write but will run. Then we handed our agents a second, newer, less-scrutinized supply chain — plugin marketplaces — and wired them to auto-update.
Every npm supply-chain lesson applies, plus a new one: an agent plugin runs with your agent's powers. File access, shell, your repo, sometimes your cloud creds. A malicious web dependency ships bad code to a browser. A malicious agent plugin ships bad code to the thing that has a terminal.
A 5-minute audit for your own setup
- List what's installed and where it comes from. Every plugin, its source repo, and whether it auto-updates. Unknown maintainer + auto-update = your top risk.
- Pin to a build you trust, and turn off silent auto-update for anything third-party. Update on your schedule, after you look.
- Verify pins as results, not requests. If your own tooling pins dependencies by SHA, confirm the checked-out tree's hash equals the pin — don't trust the "installed X" log line. (This is the exact bug; don't reinvent it.)
- Give the agent least privilege. If a plugin doesn't need your AWS creds or your whole home directory, don't run the agent where it can reach them.
- Prefer first-party / well-audited plugins. "It has a nice README" is how the last supply-chain era went too.
Plugin4Shell will get a patch everywhere eventually and fade from the feed. The pattern won't: we're bolting fast-moving, auto-updating, high-privilege extension systems onto tools that can run code, and treating "pinned" as if it means "verified." It doesn't unless someone checks.
Go check what plugins your coding agent auto-updates — did you even know the full list? Drop what you found (and your Claude Code / Codex version) below. 👇
I write about building with AI and the honest ways it breaks. Follow me here if that's your lane. 👋
Top comments (1)
Some comments have been hidden by the post's author - find out more