← Founder Notes
Archive

A zero-click remote code execution flaw called plugin4shell hit claude code, codex, copilot, and…

Yethikrishna ROriginal on Threads

a zero-click remote code execution flaw called plugin4shell hit claude code, codex, copilot, and gemini cli on september 18 through malicious plugin updates, no click or approval needed. the attack surface moved from the model to the update path.

every coding agent is now a supply chain.

Context

Air Security's post of 17 September 2026 describes a plugin SHA-pinning bypass: the agent checks out the commit the marketplace pinned but never verifies it landed there, so an attacker who controls a plugin's repository can make the checkout resolve to malicious code while the pin looks honored. It says the zero-click case depends on plugin auto-update, the default in Claude Code and Codex, and lists Claude Code, Codex, GitHub Copilot and Gemini CLI as affected, Gemini with a different variant. It says Anthropic patched Claude Code after disclosure, in 2.1.179.

How it compares

This is the same finding as the earlier note linked here, with the Claude Code fix now stated. It requires a plugin the user already installed from a marketplace whose repository the attacker controls, so it is not a blanket remote code execution on any machine running these agents. Other vendors' fix versions were not located in the text read. No evidence of exploitation in the wild was read, so it is a disclosed research finding. Sources differ on the disclosure date, 17 or 18 September; the first-party blog is dated 17 September. Air also sells security products. Every coding agent being a supply chain is the author's opinion.

Related work

Watch next

  • Vendor advisories and CVE identifiers.

Sources

  1. Plugin4Shell (Air Security, 17 Sep 2026)air.security

Provenance

The note above is reproduced unedited from the original post, first published on Threads on 19 September 2026 at 01:47 IST. Sources are the papers and datasets the note draws on.

View the original post
Embed this note
<iframe src="https://founder.myndlabs.tech/notes/embed/a-zero-click-remote-code-execution-flaw-called-DdcRi3VF49r" width="480" height="420" style="border:0;max-width:100%" loading="lazy" title="A zero-click remote code execution flaw called plugin4shell hit claude code, codex, copilot, and…"></iframe>

More notes