Security firm air found claude code, codex, gemini cli, and copilot share one logical flaw in how…
security firm air found claude code, codex, gemini cli, and copilot share one logical flaw in how they load skills. all four agents have the same weakness in the same place.
the agent ecosystem just got its first industry-wide vulnerability.
Context
Air Security's post of 17 September 2026, named Plugin4Shell, describes a plugin SHA-pinning bypass: agents check out the marketplace-pinned commit but do not verify the checkout landed on that commit, so an attacker-controlled repository can make it resolve to malicious code. Air calls it zero-click RCE, with auto-update on by default in Claude Code and Codex. In Claude Code, Codex and GitHub Copilot a branch named like the pinned hash is preferred over the commit, and Gemini CLI has a different variant. A Cloud Security Alliance research note says Air disclosed it on 18 September 2026.
This is the researching vendor's own report, not independent. Air frames it as a plugin and marketplace flaw, not skills, which it mentions only in earlier research. The same weakness in the same place is Air's single design error claim, though Gemini CLI's variant differs. First industry-wide vulnerability is Air's own claim of the first supply chain vulnerability of the AI agent ecosystem. Per-tool versions, patch status, vendor responses and CVE identifiers were not found. The Air page is dated 17 September while CSA gives 18 September for disclosure.
Related work
- Plugin4Shell zero-click RCE (The Next Web) ↗Snippet only.
- Plugin4Shell pinned SHA bypass (Threat Frontier) ↗Snippet only.
Watch next
- Vendor advisories and fixed versions for each tool.
Sources
- Plugin4Shell (Air Security, 17 Sep 2026)air.security
- Plugin4Shell research note (Cloud Security Alliance)labs.cloudsecurityalliance.org
Provenance
The note above is reproduced unedited from the original post, first published on Threads on 18 September 2026 at 06:48 IST. Sources are the papers and datasets the note draws on.
View the original post ↗Embed this note
More notes
The air is now being asked to keep its own ledger
the air is now being asked to keep its own ledger: ecmwf’s aifs compo becomes the first ai model to forecast atmospheric composition globally every three hours, cleanair simulates 365 days of pm2.5 over china in ten seconds, and a unified framework maps six pollutants at one kilometer across the whole country. the air now files its own composition report.
read the note →The current is now being asked to draw its own map
the current is now being asked to draw its own map: china’s langya 2.0 predicts six ocean phenomena including internal waves and mesoscale eddies, a deep net called wenhai resolves eddies globally with air sea flux formulas built in, and scripps infers surface currents from the way temperature patterns deform in satellite images. the ocean now files its own circulation report.
read the note →The soil is now being asked to report its own carbon
the soil is now being asked to report its own carbon: a nix color sensor paired with generative data augmentation predicts soil organic carbon without a lab, random forest drives 74 percent of soil health mapping studies, and sentinel 2 tracks five year carbon change across france and italy from 922 samples. the dirt now files its own carbon account.
read the note →