Dashboard

When Your AI Coding Tool Updates a Plugin Behind You

A disclosure this month showed four major AI coding agents checking out plugin code that was never the code they pinned. The mechanism is worth understanding, because the assumption it broke is one almost everyone makes.

Cecilia Iona
Cecilia Iona
Senior Editor, AI & Product
21 September 20261 min read

On 17 September 2026 researchers at AIR disclosed Plugin4Shell, a zero-click remote code execution flaw in the plugin systems of Claude Code, OpenAI Codex, GitHub Copilot and Gemini CLI. The detail that makes it worth your time is not the severity rating. It is the assumption that broke. All four tools pinned plugins to a specific reviewed commit, which is the correct thing to do, and all four then failed to check that the code they ended up with was the code they pinned.

What a Plugin Supply Chain Attack Actually Is

A supply chain attack does not target you. It targets something you already decided to trust, and arrives through the door you opened for it. In the AI coding agent version, the trusted thing is a plugin: a small package that extends what your agent can do, installed once, updated automatically thereafter.

The attack has a shape that repeats across ecosystems:

  1. Publish something genuinely useful under a plausible name, and let it pass whatever review exists.

  2. Wait for adoption. Adoption is the payload delivery mechanism, so the longer the wait, the wider the blast radius.

  3. Change the upstream code, or take over a repository whose maintainer has moved on.

  4. Let the victims' own automatic updates do the distribution.

Nothing in that sequence requires the victim to click anything, which is what "zero-click" means here. Help Net Security's account of the disclosure notes the same pattern appearing alongside a related campaign in which hijacked skills reached roughly 134,000 agents.

Why SHA Pinning Did Not Save Anyone

Pinning to a commit hash is supposed to close exactly this hole. A commit hash is content-addressed: change so much as a character of the code and the hash changes, so a pinned hash should mean the code you reviewed is the code you get, forever, regardless of what happens upstream.

The flaw was in the step after the pin. Git lets a branch be named almost anything, including a string that looks exactly like a 40-character commit hash. If an attacker creates a branch with that name, a checkout for the "hash" can resolve to the branch instead, and land on entirely different code. As AIR's write-up puts it, every one of the four agents checked out the pinned commit without verifying the checkout landed there.

The pin was recorded. The pin was even honoured, in the sense that the right string was passed to the right command. Nobody asked the one follow-up question that mattered:

bash
# The pattern that failed: trust the request
git checkout <pinned-sha>
# ... and proceed

# The pattern that holds: verify the result
git checkout <pinned-sha>
actual=$(git rev-parse HEAD)
[ "$actual" = "<pinned-sha>" ] || exit 1

This is the generalisable lesson, and it is worth more than the CVE. A security control that issues an instruction and never confirms the outcome is a control in name only. The same shape appears in permissions that are requested but never checked, and allowlists that are configured but never enforced.

Where the Four Tools Stand

Tool

Status

Claude Code (Anthropic)

Patched in 2.1.179

Codex (OpenAI)

Patched in 0.146.0

GitHub Copilot (Microsoft)

No patch shipped at time of writing

Gemini CLI (Google)

Deprecated rather than patched; existing installs remain exposed

AIR reported to all four vendors in June 2026 under a 90-day disclosure window, which is why publication landed in September. Google's answer was to point users at Antigravity, built without the plugin pinning system in question, rather than to fix the deprecated client. The Register's coverage frames the potential reach plainly: an agent running as you has your reach, which is source code, API keys, CI credentials and whatever cloud access your session carries.

What to Actually Check in Your Own Setup

Two of the four have patches, so the first step is unglamorous and effective:

  • Update Claude Code to 2.1.179 or later, and Codex to 0.146.0 or later. Check the version you are running rather than assuming your installer kept up.

  • If you use Gemini CLI, it is not getting a fix. Migrate or stop using its plugin system.

  • Inventory the plugins you have installed and remove the ones you stopped using. An unused plugin still updates.

  • Turn off automatic plugin updates where the tool allows it, at least for plugins you did not write, and accept the friction of updating deliberately.

  • Check who owns each plugin repository now, not who owned it when you installed it. Maintainer handover is the quiet half of this attack class.

If you are vetting a new extension, the questions are the same ones worth asking of any MCP server before you connect it: who publishes it, what does it get access to, and what happens if that account is compromised tomorrow.

The Broader Point About Agent Blast Radius

Every one of these attacks is worth exactly as much as the access the agent holds. An agent confined to a scratch directory with no credentials is a nuisance to compromise. An agent with your shell, your repository and your environment variables is a full account takeover waiting for a trigger. That is an argument for scoping agent access deliberately rather than generously, which is the same reasoning behind keeping a coding agent away from your production database.

Set against the wider set of risks that come with AI systems, this one is unusual in a useful way: it is not a model behaving unpredictably, it is ordinary software supply chain risk arriving through a new door. That makes it tractable with methods the industry already has.

It is also worth separating this from the more familiar worry about agents writing insecure code. That risk is real and catching a coding agent introducing a vulnerability is its own discipline. Plugin4Shell is a different category: the agent wrote nothing wrong. The tool around it fetched code nobody approved and ran it with your permissions.

Frequently Asked Questions

What is Plugin4Shell?

A zero-click remote code execution vulnerability in the plugin systems of Claude Code, Codex, GitHub Copilot and Gemini CLI, disclosed by AIR in September 2026. It let a malicious plugin update run code without any user action.

Why did pinning to a commit hash not prevent it?

Because a Git branch can be named to look like a commit hash, and the agents did not verify that the checkout actually landed on the pinned commit. The pin was requested but never confirmed.

Which versions are safe?

Claude Code 2.1.179 and later, and Codex 0.146.0 and later. GitHub Copilot had no patch at the time of writing, and Gemini CLI was deprecated instead of fixed.

Do I need to reinstall my plugins?

Updating the agent addresses the checkout flaw. Separately, audit which plugins you have, remove unused ones, and check current repository ownership, since a hijacked plugin is a problem independent of this bug.

Does this mean plugins are unsafe in general?

No, it means automatic updates of third-party code carry the risk they have always carried in every package ecosystem. The mitigation is the ordinary one: fewer dependencies, deliberate updates, and access scoped so a compromise is survivable.

How did this land?

About the author

Cecilia Iona
Cecilia Iona

Senior Editor, AI & Product

Cecilia leads the Swarmz editorial desk. She has spent a decade turning complex AI and product topics into writing people actually finish, and she owns the blog's quality bar.

Share

Get the next post in your inbox

One email a month. Product updates, engineering posts, and the best of Built with Swarmz.

I agree to receive emails about AI building tips and Swarmz product news. Unsubscribe any time.