Plugin4Shell is a newly disclosed supply-chain vulnerability in the plugin installation logic used by several major AI coding agents. Security researchers at AIR disclosed the issue publicly on September 17, 2026 after coordinated vendor disclosure. The important point is not that the underlying AI models were hacked: the flaw sits in how agent clients resolve and verify plugin code before running it.
The products named by the researchers are Anthropic Claude Code, OpenAI Codex, GitHub Copilot, and Google Gemini CLI. Anthropic and OpenAI have patched their clients. GitHub Copilot did not have an equivalent agent-side fix at public disclosure, while Google has been moving individual users from Gemini CLI to Antigravity CLI. Google also says Gemini CLI remains supported for enterprise and paid API-key users, which makes the Gemini status more nuanced than a simple “retired for everyone” headline.
Plugin4Shell status at a glance
| Product | Status | Minimum known fixed version / guidance | What users should do |
|---|---|---|---|
| Claude Code | Patched | 2.1.179 | Update Claude Code to 2.1.179 or later and verify your installed version. |
| OpenAI Codex | Patched | 0.146.0 | Update Codex to 0.146.0 or later. |
| GitHub Copilot | No equivalent client-side fix reported by AIR at disclosure | No fixed client version cited by AIR | Reduce plugin exposure, prefer repositories and hosting paths that block ambiguous SHA-like refs, and watch Microsoft/GitHub security guidance. |
| Gemini CLI | Consumer access transitioned to Antigravity; enterprise/API-key support continues | Google directs affected individual users to Antigravity CLI | Consumer users should migrate. Enterprise or API-key users that remain on Gemini CLI should verify current Google guidance and tightly control plugin sources. |
Source check: September 25, 2026. AI-XBlog rechecked AIR Security’s disclosure and current vendor guidance. The minimum fixed versions reported by AIR remain Claude Code 2.1.179 and Codex 0.146.0; vendor status can change quickly, so verify the latest client release and advisory before relying on these thresholds.
What changed?
Plugin marketplaces often pin an add-on to a specific Git commit SHA so the reviewed code should stay identical after installation. AIR found that the affected agent clients could request the pinned commit without performing a final check that the working tree actually resolved to that exact commit. Under specific repository-hosting conditions, an attacker who already controls the plugin repository could make the client resolve a different ref and run different code while the pin still appeared to be honored.
That matters because coding-agent plugins can inherit the same local permissions available to the agent: source code, environment variables, developer credentials, internal repositories, cloud tooling, or CI resources. A compromised plugin therefore does not need a separate privilege-escalation bug to create a serious blast radius.
Why it can become zero-click
The dangerous part is background plugin updating. AIR says Claude Code and Codex can update installed plugins automatically. If an already-trusted plugin repository is later compromised, malicious code could reach an existing installation without requiring the developer to approve a new plugin at that moment. This is why the disclosure is being described as a supply-chain problem rather than a normal prompt-injection issue.
There is an important limitation: the demonstrated Claude Code/Codex/Copilot path depends on Git reference behavior and repository hosting. GitHub blocks branch names that look like a full 40-character SHA, which reduces that particular path for GitHub-hosted plugin repositories. Bitbucket and some self-hosted Git servers can permit the naming pattern. The Gemini CLI variant is different and involves how its plugin flow resolves FETCH_HEAD.
Previous vs. new security assumption
| Previous assumption | What Plugin4Shell shows |
|---|---|
| Pinning a plugin to a reviewed commit is enough to guarantee the installed code. | The client must also verify the final checked-out commit after resolution. |
| A marketplace review protects users after install. | Repository compromise plus background updates can bypass the original trust decision. |
| Agent security is mainly about prompts, permissions, and model behavior. | The plugin and extension supply chain is now part of the agent security boundary. |
| A benign plugin remains benign if its pinned SHA does not change. | The pin itself is not a sufficient guarantee if the client does not verify the resolved working tree. |
Claude Code: update to 2.1.179 or later
AIR says Anthropic fixed the issue in Claude Code 2.1.179. Users on an older build should update before relying on marketplace plugin pinning as an integrity control. The fix is especially relevant for teams that use plugins from Bitbucket or self-hosted Git repositories rather than only GitHub-hosted sources.
If you use Claude Code for broader multi-step development workflows, see our Claude Code Projects guide and our Cursor vs Claude Code comparison.
OpenAI Codex: update to 0.146.0 or later
AIR reports that OpenAI fixed the issue in Codex 0.146.0. The underlying protection is conceptually simple but important: after a plugin checkout, the client verifies that the resolved commit is actually the one that was pinned. This closes the trust gap between “the commit we asked Git for” and “the code that is now on disk.”
For broader OpenAI agent architecture and sandboxing considerations, see our OpenAI Agents API guide.
GitHub Copilot: the hosting detail matters
AIR said Microsoft/GitHub had not shipped an equivalent client-side patch when the research became public. That does not mean every Copilot plugin installation is automatically exploitable. GitHub itself rejects full SHA-shaped branch names, which blocks the demonstrated branch-name technique for repositories hosted on GitHub. The remaining concern is architectural: if the client trusts a requested pin without verifying the final resolved commit, protection can depend on the behavior of the repository host.
For organizations using Copilot extensions or plugins from non-GitHub sources, the conservative response is to restrict plugin sources, disable unnecessary auto-update paths, review repository ownership, and follow Microsoft/GitHub security advisories for a client-side verification fix.
Gemini CLI: consumer migration and enterprise nuance
Many reports summarize the Google response as “Gemini CLI is deprecated, move to Antigravity.” That is only fully accurate for individual consumer access. Google announced that Gemini CLI stopped serving requests for Google AI Pro, Ultra, and free individual users on June 18, 2026 and directed those users to Antigravity CLI.
However, Google also states that Gemini CLI remains supported for organizations using Gemini Code Assist Standard or Enterprise and for developers authenticating with paid Gemini or enterprise-platform API keys. AIR says Google did not plan to patch the disclosed Plugin4Shell path in Gemini CLI. Enterprise users who continue using Gemini CLI should therefore verify the latest Google security status directly and tightly control plugin repositories rather than assuming the consumer migration announcement removed their exposure.
What developers and teams should do now
- Inventory client versions. Verify Claude Code is 2.1.179 or later and Codex is 0.146.0 or later.
- Inventory installed plugins and their repository hosts. Do not treat a marketplace listing as the only trust boundary.
- Reduce background auto-update exposure on products that do not yet verify the final checked-out commit.
- Prefer least-privilege agent environments. A plugin should not automatically inherit unrestricted production credentials simply because the coding agent can reach them.
- Separate developer and production credentials. Use short-lived credentials, scoped tokens, isolated CI identities, and restricted secret access.
- Monitor vendor advisories. Patch status can change faster than a normal evergreen article.
Practical implications for AI agent security
Plugin4Shell is important because it shifts the security discussion below the model layer. Prompt injection, tool permissions, sandboxing, approval gates, and model safeguards remain important, but none of them can compensate for silently executing compromised plugin code with the same privileges as the agent host.
The long-term control is straightforward: the agent must verify the exact code it resolved before execution, and organizations should assume agent add-ons are software supply-chain dependencies rather than harmless prompt extensions. This fits the broader architecture described in our AI Agent Security in 2026 guide.
Was Plugin4Shell exploited in the wild?
AIR demonstrated working proof-of-concept paths and separately documented earlier plugin-repository hijacking research. As of this source check, we did not find a reliable public report confirming widespread in-the-wild exploitation of Plugin4Shell itself. That distinction matters: the vulnerability and demonstrated attack path are real, but public proof of active mass exploitation is a separate question.
Does Plugin4Shell affect the AI models themselves?
No. This disclosure is about the coding-agent clients and their plugin supply chain, not a vulnerability in Claude, GPT, Gemini, or Copilot model weights. The models are relevant because the agent products can run tools and code, but the security failure described by AIR is in plugin integrity verification.
Sources
- AIR Security — Plugin4Shell technical disclosure
- Help Net Security — affected agents and patch status
- The Register — independent coverage
- Google Developers Blog — Gemini CLI to Antigravity transition
AI-XBlog Weekly Brief
Keep up with AI that actually works
Join the AI-XBlog Weekly Brief for major AI updates, practical workflows, useful tools, and editor’s picks. No daily noise.
Reader discussion
Join the discussion
Have you tried this tool or workflow? Share your experience, corrections, or questions. Useful reader feedback may help us improve this article.
All comments are reviewed before publication. Your email address will not be published. Promotional links and low-value spam are removed.
