If you use AI coding agents and assumed that pinning a plugin to a specific commit hash guaranteed you were running verified code, Plugin4Shell just invalidated that assumption.
What the Vulnerability Does
Discovered by AIR Security, Plugin4Shell is a high-severity, zero-click remote code execution flaw affecting Claude Code, OpenAI Codex, GitHub Copilot, and the Gemini CLI. The root cause is a verification gap: these agents perform a git checkout using a pinned 40-character commit SHA, but they never confirm that the resulting working tree actually matches that hash.
An attacker who controls a plugin repository can create a branch named identically to the pinned SHA and set it as the repository default. Git resolves branch names before commit hashes, so the agent silently checks out the malicious branch while believing it loaded the pinned, verified version.
Why It Is Zero-Click
Claude Code and Codex both run background auto-updates that re-execute the checkout process when a marketplace bumps a pinned SHA. If the malicious branch is already staged, the swap happens without any user interaction or notification. The end user sees nothing.
Patch Status
- Claude Code: patched in version 2.1.179
- OpenAI Codex: patched in version 0.146.0
- GitHub Copilot: unpatched as of this report
- Gemini CLI: Google has deprecated the CLI entirely and is advising users to migrate to Antigravity rather than issuing a fix
Because the flaw lives inside the agent software itself, plugin marketplaces cannot enforce the security guarantees they advertise. The only viable mitigation is updating the agent.
The Broader Pattern
AIR Security’s previous research showed how malicious skills spread virally to seize control of over 26,000 agents, and how attackers can hijack legitimate repositories without planting new code. Plugin4Shell follows earlier supply-chain incidents including the LiteLLM breach and a Sentry MCP SSRF vulnerability. This one represents the failure of SHA pinning itself, not just the repositories or models around it.
The technical fix is straightforward: after checkout, the agent should resolve the actual commit in the working tree and abort if it does not match the pinned SHA. Until that check is standard across all agents, the plugin distribution layer remains an open attack surface.
