Plugin4Shell: newly disclosed plugin vulnerability hits Codex, Claude Code, GitHub Copilot and Gemini CLI
Air Security disclosed Plugin4Shell, a plugin version-verification flaw affecting Claude Code, OpenAI Codex, GitHub Copilot, and Gemini CLI; patches are out for Claude Code and Codex.
What happened
Security firm Air Security has disclosed "Plugin4Shell," a vulnerability in widely used AI coding agents including Claude Code, OpenAI Codex, GitHub Copilot, and Gemini CLI, reported September 29, 2026. The flaw sits in software version verification: plugin marketplaces are supposed to lock extensions to a specific verified version, but Air Security found that safeguard can be bypassed when an attacker controls or takes over the underlying codebase — letting them replace a seemingly harmless, verified plugin with malicious code.
Why it matters
In certain configurations, the agents automatically update already-installed extensions, so a compromised plugin could land on developer machines with no new-install confirmation or link click. Once executed, it inherits the agent's permissions and can reach the data or systems the agent is allowed to touch — a supply-chain-style attack vector for agent workflows.
Who's patched, who isn't
Per Air Security's report, Anthropic and OpenAI have released corrected versions: Claude Code from version 2.1.179 and Codex from version 0.146.0. At the time of publication, no patch was available for GitHub Copilot. Google will no longer update Gemini CLI — Air Security reports the tool is being discontinued, and users are advised to switch to another product.
What to do now
The report recommends promptly updating deployed agents, centrally reviewing installed plugins, automatic-update behavior, and access rights, and adding internal approval processes for extensions — since the issue isn't limited to obviously fraudulent downloads.
Verified September 30, 2026
Sources
- ReportB2B Cyber Security