In brief

Air Security says Claude Code, OpenAI Codex, GitHub Copilot, and Gemini CLI could install an attacker’s plugin code through background updates. Anthropic and OpenAI fixed it. Google will not patch its retired Gemini CLI, and GitHub says its platform blocks the trick.

New to this? Read it in simple words
  • Air Security reported a flaw called Plugin4Shell on September 17. It says four AI coding agents could install an attacker’s code without any click.
  • Anthropic and OpenAI have fixed it in Claude Code and Codex. Google will not fix Gemini CLI, because the tool is retired.
  • The agents asked for one exact plugin version but did not check what they received. Developers should update their agents and check which plugins can update themselves.
  • GitHub disagrees that Copilot is exposed. A German tech site reports that no real attacks are known.
Words to know
Plugin
An extra piece of software that adds new features to a program.
AI agent
An AI that takes steps on its own to finish a task, such as booking or coding.

A version pin that nobody checked

Researchers at Air Security published a flaw called Plugin4Shell on September 17. It affected the plugin systems of four AI coding agents: Claude Code, OpenAI Codex, GitHub Copilot, and Gemini CLI.

Plugin marketplaces pin each plugin to one exact version, marked by a long code called a commit hash. The agents asked for that version, but they did not confirm that they received it.

An attacker who controls a plugin’s code repository could create a branch with the same name as that hash. The git tool would then pick the attacker’s branch, and the agent would install that code.

Sources13

PLUGIN PATH 09
A branch named like a commit hash can replace a pinned plugin during a background update.

Anthropic and OpenAI fixed the check. Google will not patch its retired Gemini CLI.

Background updates made it zero-click

The attack needed no action from the user, because the agents update plugins in the background. Air says this setting is on by default in Claude Code and Codex.

Air says the trick works on code hosts that allow such branch names, such as Bitbucket and self-hosted git servers. GitHub itself rejects these names.

The German tech site heise reports that no real attacks are known. None of the coverage we read listed an official CVE number, the standard ID for a public security flaw.

Sources145

The vendors responded in different ways

Air and heise report that Anthropic fixed the flaw in Claude Code version 2.1.179 in June. OpenAI’s release notes for Codex 0.146.0, published in July, list a change that checks plugin checkouts against the pinned commit.

Google told Air it will not patch Gemini CLI because the tool is retired, and pointed users to its newer tool, Antigravity. GitHub told The Register that it blocks branch names that look like commit hashes, so the attack cannot work on GitHub.

Air says Copilot remains exposed through marketplaces on other platforms. Air also sells security products for AI agents, so its claims about scale need independent checks. Developers should update their agents and review which plugins can update themselves.

Sources1234

Sources

Every fact in this story comes from the sources below. Open them to check our work.

  1. 1
  2. 2
    Primary source · July 29, 2026Release 0.146.0 · openai/codex OpenAI on GitHub
  3. 3
  4. 4
  5. 5
How we checked this story

We read Air Security’s technical report and OpenAI’s Codex release notes, then compared them with The Register, heise, and InfoWorld. Air sells security tools for AI agents, so we separate its claims about scale from the confirmed fixes. Nobody has measured the number of affected users independently.