Source · DiggingBeagle record
Plugin4Shell - Zero Click RCE Vulnerability found in top 4 most popular coding agents
Primary Plugin4Shell technical disclosure describing the plugin SHA-pinning bypass, the SHA-shaped default-branch and FETCH_HEAD variants, zero-click background-update path, affected coding agents and vendor remediation status.
- Published
- Sep 17, 2026
- Accessed
- Sep 19, 2026
- Publisher
- AIR Security
Each support, contradiction or context label applies to a cited Claim, not to a whole Case.
Source record
Primary Plugin4Shell technical disclosure describing the plugin SHA-pinning bypass, the SHA-shaped default-branch and FETCH_HEAD variants, zero-click background-update path, affected coding agents and vendor remediation status.
Claim-level citations (8)
- supportsPlugin4Shell let pinned AI-agent plugins resolve to different attacker-controlled code: AIR reports Claude Code fixed in 2.1.179 and Codex fixed in 0.146.0; OpenAI's public Codex change verifies resolved HEAD after checkout and rejects a mismatch.
Vendor status and remediation section
- supportsPlugin4Shell let pinned AI-agent plugins resolve to different attacker-controlled code: The common integrity failure is that the client requests a pinned commit but does not verify that the final checked-out HEAD equals the commit identity the marketplace approved.
Technical deep dive: pinned commit checkout and missing post-checkout verification
- supportsPlugin4Shell let pinned AI-agent plugins resolve to different attacker-controlled code: For Claude Code, Codex and GitHub Copilot, AIR demonstrated a variant where a default branch named exactly like the pinned 40-hex commit can win Git name resolution on hosts that permit such branch names.
Technical deep dive: The pinned commit becomes a branch - Claude Code, Codex, GitHub Copilot
- supportsPlugin4Shell let pinned AI-agent plugins resolve to different attacker-controlled code: AIR describes the attack as zero-click for already-installed plugins where background auto-update re-runs the vulnerable checkout path, including default update behavior reported for Claude Code and Codex.
Background auto-update discussion in the Claude and Codex variant
- supportsPlugin4Shell let pinned AI-agent plugins resolve to different attacker-controlled code: AIR Security reported working Plugin4Shell proof-of-concept attacks against Claude Code, OpenAI Codex, GitHub Copilot and Gemini CLI.
Disclosure introduction and affected-agent proof-of-concept sections
- supportsPlugin4Shell let pinned AI-agent plugins resolve to different attacker-controlled code: The SHA-shaped-branch variant is not exploitable through default GitHub-hosted repositories because GitHub rejects branch or tag names that resemble commit SHAs; AIR says other supported hosts such as Bitbucket or self-hosted Git can still permit the condition.
Host-condition discussion for 40-hex default branches
- contextPlugin4Shell let pinned AI-agent plugins resolve to different attacker-controlled code: The cited public material establishes reproducible proof of concept but does not establish exploitation of Plugin4Shell in the wild.
Research disclosure presents proof-of-concept attack paths rather than victim incident reporting
- supportsPlugin4Shell let pinned AI-agent plugins resolve to different attacker-controlled code: Gemini CLI had a separate variant: it fetched the pinned commit but then checked out FETCH_HEAD without verifying the resolved object, allowing a default branch named FETCH_HEAD to redirect the working tree.
Technical deep dive: The pin is fetched but never checked out - Gemini CLI
Cite this record
DiggingBeagle. “Plugin4Shell - Zero Click RCE Vulnerability found in top 4 most popular coding agents.” Published Sep 17, 2026 · Accessed Sep 19, 2026. https://diggingbeagle.com/sources/plugin4shell-zero-click-rce-vulnerability-found-in-top-4-most-popular-coding-age/
Citation guidance