Plugin4Shell: AI Coding Agent Supply Chain Vulnerability
Score: 7/10

Plugin4Shell: AI Coding Agent Supply Chain Vulnerability

A flaw in major AI coding agents allows attackers to bypass SHA-pinning and execute zero-click remote code by swapping trusted plugins with malicious code via branch-name manipulation.

Executive Summary

Plugin4Shell is a high-severity, zero-click Remote Code Execution (RCE) vulnerability affecting the distribution layer of the AI coding agent ecosystem, including Claude Code, OpenAI Codex, GitHub Copilot, and Gemini CLI. The vulnerability stems from a design error where agents fail to verify that the code checked out from a repository actually matches the pinned commit SHA. By creating a branch named identically to the pinned SHA on platforms like Bitbucket or self-hosted Git servers, an attacker can force the agent to install malicious code while appearing to honor the security pin.

The impact is significant because plugins inherit the full permissions of the employee operating the agent, providing attackers access to sensitive internal data and production environments. Furthermore, because background auto-updates are often enabled by default, an attacker who takes over a legitimate plugin repository can push malicious code to millions of agents without any user interaction.

While Anthropic and OpenAI have released patches for Claude Code and Codex respectively, GitHub Copilot remains unpatched for non-GitHub hosted plugins, and Google has deprecated Gemini CLI without a fix. Organizations are urged to update affected agents and migrate away from deprecated tools.

Key Details

Threat Name

Plugin4Shell

Affects

—

Adversary

—

MITRE Techniques

Malware/Tools

Plugin4Shell

Report Score

7out of 10
Quality Score
Good
IOC Quality2
TTP Details9
Detection Guidance5
Enterprise Relevance10
Clarity & Structure9
Technical Depth9

Sources