Zero-Click RCE Flaw in AI Coding Agents: Plugin4Shell
A zero-click remote code execution (RCE) flaw, dubbed Plugin4Shell, was discovered in popular AI coding agents such as OpenAI's Codex, Anthropic's Claude Code, Google's Gemini CLI, and Microsoft-owned GitHub Copilot. This vulnerability allowed attackers to execute malicious code without developer interaction by swapping a trusted plugin with a malicious one, potentially gaining a foothold in enterprise development environments. Researchers at AIR reported the flaw to the vendors, and most have released patches. Users must update their agents to mitigate the risk.