important · Developer tools — Codex
A repository takeover could turn a Codex background plugin update into developer-context code execution.
Affects
Codex CLI, OpenAI's cross-platform local coding agent and plugin host.
The demonstrated chain combines an installed plugin, repository control, a marketplace repin, a Git backend that permits a SHA-shaped branch, and background updates; Codex accepted a resolved HEAD that differed from the pinned commit.
Detail and 5 sources
Codex 0.146.0 includes a regression-tested fix, and AIR reports verifying it against the end-to-end demonstration.
Sources
ResearchPlugin4Shell: SHA-Pinning Bypass Enables AI Coding Agent RCE – Lab SpaceResearchAIコーディングエージェント4製品に共通の脆弱性「Plugin4Shell」— プラグインのSHA固定を迂回し、無操作で悪性コードを実行させる手法をAIRが公表 | NEXSIGHT CYBER WIRECode / PoCVerify Git plugin SHA checkouts by copyberry[bot] · Pull Request #34644 · openai/codexCode / PoCRelease 0.146.0 · openai/codexVendorPlugin4Shell - Zero Click RCE Vulnerability found in top 4 most popular coding agents, millions of agents affected