Skip to finding
§
High
AI supply chain
Confirmed

Plugin4Shell defeats commit-like pinning in four AI coding agents.

The chain is demonstrated; remediation across the four agents remains partial.

Affects

Claude Code, OpenAI Codex, GitHub Copilot, and Gemini CLI plugin or extension installers on developer workstations.

What it enables

Zero-click execution of repository-controlled plugin code with the coding-agent user's privileges

Attacker controls a plugin repository or later compromises a previously benign plugin.→↓A marketplace record or local installation pins a reviewed commit identifier.→↓The attacker creates a SHA-shaped branch, or abuses Gemini CLI's FETCH_HEAD behavior, so the symbolic checkout resolves to malicious content.→↓The agent updates the installed plugin without verifying that HEAD equals the pinned commit.→↓Plugin-controlled hooks or commands execute with the coding-agent user's privileges.
Why this matters

A repository owner or later compromise can replace reviewed plugin code and obtain zero-click execution with the coding-agent user's privileges.

Detail, proof-of-concept code and 6 sources
Required access

Control a plugin repository already installed by the victim, using a source that accepts SHA-shaped branch names; Gemini CLI is affected through a related FETCH_HEAD path.

Affected versions

Claude Code before 2.1.179, OpenAI Codex before 0.146.0, GitHub Copilot plugin installer as of 2026-09-20, Gemini CLI plugin installer as of 2026-09-20

A SHA-shaped branch can win Git's ambiguous reference resolution, while Gemini CLI has a related FETCH_HEAD path; the agents accepted the materialized checkout without proving that HEAD matched the pin.

OpenAI added an exact post-checkout comparison, and OpenAI and Anthropic published fixed releases, but the cross-agent condition is not fully closed.

Evidence
Air Security's original research demonstrates exploitation against all four agents and documents the source-host prerequisite.OpenAI's corrective pull request adds post-checkout commit verification.OpenAI and Anthropic published fixed releases.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, September 20, 2026