system: OPERATIONAL
← back to all hacks
SUPPLY CHAIN CRITICAL NEW

Plugin4Shell: a SHA-pinning bypass turns coding-agent auto-update into RCE

AIR Security (17 Sep 2026) found a zero-click flaw letting a trusted plugin update silently swap in malicious code in Claude Code, Codex, Copilot and Gemini CLI.

2026-09-25 // 6 min affects: claude-code, codex, github-copilot, gemini-cli

What is this?

On 17-18 September 2026, researchers Or Nevo, Dor Granat and Niv Hoffman at AIR Security published Plugin4Shell, a zero-click remote code execution flaw in the plugin-installation logic of four widely used AI coding agents: Claude Code (Anthropic), Codex (OpenAI), GitHub Copilot (Microsoft) and Gemini CLI (Google). The finding was discovered in May 2026 and disclosed to the vendors in June 2026, so the public write-up follows the standard 90-day-plus responsible-disclosure window. AIR Security describes it as one of the first documented supply-chain vulnerabilities specific to the AI agent ecosystem.

The bug does not touch model weights or prompts. It targets SHA-pinning: the practice, used by every one of these agents’ plugin marketplaces, of locking an installed extension to the exact commit hash that a reviewer approved — precisely so a later, unreviewed update cannot silently change what actually gets installed.

How it works

The four agents fail the same underlying check in two different ways, both rooted in how git checkout resolves names.

For Claude Code, Codex and GitHub Copilot, the agent checks out a plugin by its pinned 40-character commit hash but never confirms that the resulting working tree actually matches that commit. Git, when a branch and a commit share the same name, prefers the branch reference. An attacker who controls the plugin’s repository can therefore create a branch literally named after the reviewed hash, point it at completely different code, and set it as the repository’s default — the checkout then silently resolves to the malicious branch while the pin still looks satisfied to anything auditing the marketplace listing.

Gemini CLI breaks the same guarantee through its own path: it fetches the pinned commit into FETCH_HEAD, but checkout can be redirected to a branch of that name instead of the object that was actually fetched, discarding the pin entirely.

The attack chain requires no victim interaction: (1) an attacker publishes an innocuous plugin that passes marketplace review and gets pinned; (2) users install it; (3) the attacker ships a routine-looking update, and the marketplace re-pins to the new commit; (4) the attacker creates a same-named branch pointing to malicious code and makes it the default; (5) every installation’s background auto-update — the default behavior in Claude Code and Codex — re-runs the flawed checkout and pulls in the attacker’s code without anyone clicking anything.

Example prompt

A defensive prompt to hand your coding agent before it applies plugin updates. It re-verifies the pin after checkout instead of trusting the marketplace listing, and the hostile branch is redacted — what matters is the mismatch to look for, not a working setup.

# Defensive check — before an agent applies a plugin update
For each installed plugin, report: pinned commit hash, the hash actually
checked out (git rev-parse HEAD), and the default branch of its repository.
Flag any plugin where:
  - the checked-out HEAD differs from the pinned hash
  - a branch name equals a 40-char commit hash, e.g. [branch named like a hash]
  - the update came in through background auto-update with no review
Do not install, update, or run anything. Output the verification table only.

Why it matters

Plugin marketplaces for coding agents inherited the trust model of package registries, but the enforcement point sits in the wrong place: as AIR Security puts it, the pin is resolved inside the agent, so no marketplace-side check can substitute for a correct implementation — the fix has to ship in the agent binary itself. A plugin that “passed review” gives a false sense of durability if nothing re-verifies the pin at checkout time. Because updates apply automatically and silently, the exposure window is every machine running an affected agent with plugins installed, not just users who chose to upgrade. Coding agents also run with elevated local privileges — file system access, shell execution, credentials in the environment — so code substituted this way inherits the same reach as any other agent action.

Defenses

  • Update immediately where a fix exists: Claude Code 2.1.179 (June 2026) and Codex 0.146.0 (12 August 2026) both resolve the underlying checkout flaw.
  • GitHub Copilot has no fix as of publication — treat installed Copilot plugins as unverified and avoid installing new ones from unfamiliar publishers until Microsoft ships a patch.
  • Gemini CLI is deprecated with no fix planned; Google is directing users toward Antigravity, which does not use the same marketplace SHA-pinning mechanism.
  • Disable background plugin auto-update where your agent supports it, and re-review plugins manually before applying updates.
  • If you maintain your own plugin or extension pinning mechanism for any agent framework, verify the checked-out tree’s actual commit hash after checkout, not just that the checkout command referenced the right pin — and reject any repository where a branch name collides with a commit hash you rely on.
  • Treat plugin marketplaces as part of your software supply chain: apply the same registry-pinning and provenance scrutiny (signed commits, protected branches, no attacker-renamable default branch) you would apply to an npm or PyPI dependency.

Status

AspectDetail
Primary sourceAIR Security, Plugin4Shell, published 17-18 September 2026
ResearchersOr Nevo, Dor Granat, Niv Hoffman (AIR Security)
Discovery → disclosure → publicationMay 2026 → June 2026 → September 2026
AffectedClaude Code (Anthropic), Codex (OpenAI), GitHub Copilot (Microsoft), Gemini CLI (Google)
AnthropicPatched — Claude Code 2.1.179 (June 2026)
OpenAIPatched — Codex 0.146.0 (12 August 2026)
MicrosoftUnpatched at publication
GoogleNo fix planned — Gemini CLI deprecated, migration to Antigravity recommended

Sources