{
  "id": 8143177,
  "title": "AI coding agents' 0-click RCE flaw could hand attackers keys to the kingdom",
  "url": "https://urgent.news/2026/09/17/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-8143177",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-17T22:42:29.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/security/2026/09/17/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom/5297335"
  },
  "original_language": "en",
  "account": "A previously unknown vulnerability dubbed \"Plugin4Shell\" has been discovered in major AI coding agents such as Anthropic’s Claude Code, OpenAI’s Codex, Google’s Gemini CLI, Microsoft’s Copilot, and Microsoft-owned GitHub Copilot. This zero-click flaw enables remote code execution, potentially granting attackers full access to all assets and data within the agent's reach. The exploitation method, called a “first-of-its-kind AI supply-chain attack,” targets trusted marketplaces that host plugins for these coding agents, affecting an estimated 90 percent of Fortune 500 companies using Copilot. Despite researchers reporting the issue to all four vendors in June, Microsoft and Google - the latter of which has deprecated the Gemini CLI - have not yet released patches. Microsoft, meanwhile, does not acknowledge the vulnerability as affecting GitHub. The security issue stems from how AI agents enforce marketplaces' SHA-pinning mechanism, which locks plugins to a specific code hash instead of allowing updates. When an attacker takes control of a compromised repository, they can swap the benign plugin with malicious code, and the agent will install and execute the malicious version without user interaction.",
  "summary": "Plugin4Shell attack affects all the major coding agents, researchers say",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "AI coding agents' 0-click RCE flaw could hand attackers keys to the kingdom",
        "url": "https://urgent.news/2026/09/17/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the",
        "published": "2026-09-17T22:42:29.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}