On September 17, 2026, the security firm AIR published Plugin4Shell, a zero-click remote code execution flaw in the plugin systems of four AI coding agents: Claude Code, OpenAI Codex, GitHub Copilot and Google’s Gemini CLI. The agents let users pin a marketplace plugin to a specific, reviewed commit SHA. AIR found that the agents checked out that pin without verifying which commit it actually resolved to. Whoever controls the plugin’s repository can create a branch whose name is identical to the pinned commit hash, and git prefers the branch ref over the commit object, so the agent installs the attacker’s code while still reporting the reviewed version. A second variant hit Gemini CLI: a repository that names its default branch FETCH_HEAD makes the checkout resolve to attacker-controlled code.
AIR says it found the bug with a working proof of concept in May 2026 and disclosed it to all four vendors in June. Anthropic confirmed a fix on June 17, 2026, in Claude Code 2.1.179. The Codex fix, in version 0.146.0, was verified on August 12, 2026. Google told AIR on August 4, 2026 that no fix was coming because Gemini CLI is being deprecated. As of publication, GitHub Copilot had shipped no patch.
AIR calls it the first supply chain vulnerability of the AI agent ecosystem. That framing is arguable, but the mechanism is instructive: SHA pinning is the standard defence a careful user reaches for, and here the defence itself was the hole. The user did everything right - installed a reviewed plugin from a trusted marketplace and locked it - and still ran unreviewed code with the agent’s full permissions on their machine.
It lands two weeks after GitSpawn showed repository git configuration running code inside seven coding agents, and it rhymes with it: both bugs live in the git plumbing that agents call on the user’s behalf, not in the model. The uneven vendor response is the sober part. Two vendors patched within months, one had not after roughly three, and one chose to retire the product rather than fix it, which leaves anyone still running it exposed with no remedy coming.