Plugin4Shell exposes zero-click RCE in Claude Code, Codex, Copilot, and Gemini CLI
Plugin4Shell – Zero Click RCE Vulnerability found in top four coding agents

A new supply chain flaw, Plugin4Shell, bypasses SHA pinning in four major coding agents, enabling zero-click remote code execution. Attackers can turn a benign plugin malicious or hijack a trusted repo, and background auto-update silently installs the payload. Anthropic and OpenAI patched, but GitHub Copilot remains unpatched and Gemini CLI is deprecated, leaving millions of agents exposed.
The agent checks out the exact commit the marketplace pinned but never verifies it landed there, so an attacker who controls the plugin's repo makes the checkout resolve to malicious code while the pin still looks honored.