{
  "id": 8138962,
  "title": "AI coding agents' 0-click RCE flaw could hand attackers keys to the kingdom",
  "url": "https://urgent.news/2026/09/17/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-17T22:42:29.000Z",
  "source": {
    "name": "The Register",
    "slug": "the-register",
    "url": "https://www.theregister.com/security/2026/09/17/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom/5297335"
  },
  "original_language": "en",
  "account": "A zero-click vulnerability that enables remote code execution has been discovered in Anthropic's Claude Code, OpenAI's Codex, Google's Gemini CLI, Microsoft's Copilot, and GitHub Copilot. Dubbed \"Plugin4Shell,\" this \"first-of-its-kind AI supply-chain attack\" could grant attackers full access to all assets and data within the agent's reach. Threat hunters at Air, a security startup protecting enterprise AI agents, have dubbed this vulnerability a \"plugin SHA-pinning bypass.\" The Air researchers reported the issue to all four vendors in June, with Anthropic and OpenAI releasing patches for Claude Code 2.1.179 and Codex 0.146.0, respectively. Google has deprecated the Gemini CLI and will not patch, while Microsoft has not yet addressed the flaw in Copilot. GitHub has implemented a mitigation, but Air researchers argue it is insufficient as marketplaces can also be hosted elsewhere. The vulnerability stems from how agents enforce marketplaces' SHA-pinning mechanism, which locks plugins to a specific commit hash. When this hash is compromised by an attacker, they can replace the benign plugin with malicious code, executing code without user interaction. This flaw allows attackers to exploit the zero-click nature of the attack, as agents automatically update plugins by default.",
  "summary": "Plugin4Shell attack affects all the major coding agents, researchers say",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register Science",
        "title": "AI coding agents' 0-click RCE flaw could hand attackers keys to the kingdom",
        "url": "https://urgent.news/2026/09/17/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-8143177",
        "published": "2026-09-17T22:42:29.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}