← Founder Notes
Archive

Security firm air found claude code, codex, gemini cli, and copilot share one logical flaw in how…

Yethikrishna ROriginal on Threads

security firm air found claude code, codex, gemini cli, and copilot share one logical flaw in how they load skills. all four agents have the same weakness in the same place.

the agent ecosystem just got its first industry-wide vulnerability.

Context

Air Security's post of 17 September 2026, named Plugin4Shell, describes a plugin SHA-pinning bypass: agents check out the marketplace-pinned commit but do not verify the checkout landed on that commit, so an attacker-controlled repository can make it resolve to malicious code. Air calls it zero-click RCE, with auto-update on by default in Claude Code and Codex. In Claude Code, Codex and GitHub Copilot a branch named like the pinned hash is preferred over the commit, and Gemini CLI has a different variant. A Cloud Security Alliance research note says Air disclosed it on 18 September 2026.

How it compares

This is the researching vendor's own report, not independent. Air frames it as a plugin and marketplace flaw, not skills, which it mentions only in earlier research. The same weakness in the same place is Air's single design error claim, though Gemini CLI's variant differs. First industry-wide vulnerability is Air's own claim of the first supply chain vulnerability of the AI agent ecosystem. Per-tool versions, patch status, vendor responses and CVE identifiers were not found. The Air page is dated 17 September while CSA gives 18 September for disclosure.

Related work

Watch next

  • Vendor advisories and fixed versions for each tool.

Sources

  1. Plugin4Shell (Air Security, 17 Sep 2026)air.security
  2. Plugin4Shell research note (Cloud Security Alliance)labs.cloudsecurityalliance.org

Provenance

The note above is reproduced unedited from the original post, first published on Threads on 18 September 2026 at 06:48 IST. Sources are the papers and datasets the note draws on.

View the original post
Embed this note
<iframe src="https://founder.myndlabs.tech/notes/embed/security-firm-air-found-claude-code-codex-gemini-DdaPM2wjNPG" width="480" height="420" style="border:0;max-width:100%" loading="lazy" title="Security firm air found claude code, codex, gemini cli, and copilot share one logical flaw in how…"></iframe>

More notes