Source · DiggingBeagle record
AI coding agents' 0-click RCE flaw could hand attackers keys to the kingdom
Independent reporting on Plugin4Shell, including vendor responses, GitHub's branch-name mitigation for GitHub-hosted repositories, the absence of a Microsoft client fix at disclosure and Google's decision not to patch the deprecated Gemini CLI.
- Published
- Sep 17, 2026
- Accessed
- Sep 19, 2026
- Publisher
- The Register
Each support, contradiction or context label applies to a cited Claim, not to a whole Case.
Source record
Independent reporting on Plugin4Shell, including vendor responses, GitHub's branch-name mitigation for GitHub-hosted repositories, the absence of a Microsoft client fix at disclosure and Google's decision not to patch the deprecated Gemini CLI.
Claim-level citations (5)
- contextPlugin4Shell let pinned AI-agent plugins resolve to different attacker-controlled code: AIR describes the attack as zero-click for already-installed plugins where background auto-update re-runs the vulnerable checkout path, including default update behavior reported for Claude Code and Codex.
Explanation of zero-click plugin auto-update behavior
- supportsPlugin4Shell let pinned AI-agent plugins resolve to different attacker-controlled code: AIR Security reported working Plugin4Shell proof-of-concept attacks against Claude Code, OpenAI Codex, GitHub Copilot and Gemini CLI.
Independent report summarizing the four affected coding agents
- supportsPlugin4Shell let pinned AI-agent plugins resolve to different attacker-controlled code: The SHA-shaped-branch variant is not exploitable through default GitHub-hosted repositories because GitHub rejects branch or tag names that resemble commit SHAs; AIR says other supported hosts such as Bitbucket or self-hosted Git can still permit the condition.
GitHub response and AIR response discussing SHA-shaped branch names and non-GitHub marketplace hosts
- contextPlugin4Shell let pinned AI-agent plugins resolve to different attacker-controlled code: The cited public material establishes reproducible proof of concept but does not establish exploitation of Plugin4Shell in the wild.
Independent coverage reports the vulnerability and remediation without an observed victim campaign
- supportsPlugin4Shell let pinned AI-agent plugins resolve to different attacker-controlled code: At public disclosure, The Register reported no GitHub Copilot client fix and said Google would not patch the deprecated Gemini CLI; GitHub argued its host-side SHA-like branch restriction prevents the reported branch-name attack for GitHub-hosted repositories.
Vendor-response section covering GitHub, Microsoft and Google status
Cite this record
DiggingBeagle. “AI coding agents' 0-click RCE flaw could hand attackers keys to the kingdom.” Published Sep 17, 2026 · Accessed Sep 19, 2026. https://diggingbeagle.com/sources/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom/
Citation guidance