Plugin4Shell: SHA-pin bypass RCE hits Claude Code, Codex, Copilot, Gemini CLI
Air Security disclosed Plugin4Shell (Sept 17): agents check out a marketplace-pinned plugin SHA but never verify HEAD, so a malicious branch named like the pin can swap in code on auto-update—zero-click RCE. Claude Code (≥2.1.179) and Codex (≥0.146.0) are patched; Copilot has no fix yet, and deprecated Gemini CLI will not be patched.
