Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

A Critical 0-Click Vulnerability in AI Coding Agents: A Threat to Cybersecurity




A critical 0-click vulnerability in AI coding agents has been discovered, allowing attackers to gain access to sensitive data and systems. The Plugin4Shell vulnerability affects all major AI coding agents and has significant implications for the security of AI-powered systems. This article provides a detailed explanation of the vulnerability, its impact, and the steps being taken to mitigate it.



  • Recent research has revealed a critical 0-click vulnerability in AI coding agents called Plugin4Shell, which can grant attackers unparalleled access to sensitive data and systems.
  • The vulnerability affects all major AI coding agents, including Anthropic's Claude Code, OpenAI's Codex, Google's Gemini CLI, Microsoft's Copilot, and Microsoft-owned GitHub Copilot.
  • The Plugin4Shell vulnerability is rooted in the way AI agents enforce marketplaces' SHA-pinning mechanism, allowing attackers to bypass it and update the agent's capabilities without user knowledge or consent.
  • The attack can be carried out in two ways: by submitting a benign plugin to a trusted marketplace and later replacing it with malicious code, or by hijacking a legitimate author's repository and pushing the malicious version onto every agent that has it installed.
  • The vulnerability highlights the need for effective mitigation strategies, including regular updates, patching, and monitoring of AI-powered systems.
  • Vendors affected by the vulnerability have been working to develop patches and mitigations, including Anthropic, OpenAI, and Google, while Microsoft's Copilot remains vulnerable.
  • The GitHub community has implemented a SHA-pinning mechanism to mitigate the Plugin4Shell vulnerability, but researchers caution that it may not be sufficient to defeat the attacks.



  • The cybersecurity landscape is becoming increasingly complex, with the rapid advancement of artificial intelligence (AI) and machine learning (ML) technologies. However, with these benefits come significant risks, as recent research has revealed a critical 0-click vulnerability in AI coding agents that can grant attackers unparalleled access to sensitive data and systems. This vulnerability, dubbed "Plugin4Shell," has far-reaching implications for the security of AI-powered systems, and it is essential to understand the nature of this threat to develop effective mitigation strategies.

    The Plugin4Shell vulnerability affects all major AI coding agents, including Anthropic's Claude Code, OpenAI's Codex, Google's Gemini CLI, Microsoft's Copilot, and Microsoft-owned GitHub Copilot. This widespread impact is due to the fact that these agents rely on trusted marketplaces that host plugins, which can be exploited by attackers to gain unauthorized access to sensitive data and systems. The vulnerability is a "first-of-its-kind AI supply-chain attack," according to threat hunters at Air, a security startup focused on protecting enterprise AI agents.

    The Plugin4Shell vulnerability is rooted in the way AI agents enforce marketplaces' SHA-pinning mechanism, which locks agent plugins and skills to a specific, immutable commit hash instead of a mutable reference like a version tag or branch name. This mechanism is designed to prevent supply chain attacks, but the vulnerability allows attackers to bypass it by manipulating the plugin's repository and convincing the agent to update its plugins with malicious code. The use of agent plugins and skills makes this vulnerability particularly concerning, as it enables attackers to update the agent's capabilities without the user's knowledge or consent.

    The researchers who discovered the Plugin4Shell vulnerability, Or Nevo, Dor Granat, and Niv Hoffman, note that the attack can be carried out in two ways. In the first scenario, an attacker submits a benign plugin to a trusted marketplace, which is then reviewed and accepted. The attacker can then later replace the benign content with malicious code, effectively bypassing the SHA pinning safety mechanism. In the second scenario, the attacker hijacks a legitimate author's repository and pushes the malicious version onto every agent that has it installed, essentially taking over the agent's capabilities.

    The researchers demonstrate the feasibility of these attacks in their earlier "SkillJacking" and "RepoJacking" proof-of-concept attacks. The Plugin4Shell vulnerability has significant implications for the security of AI-powered systems, as it can enable attackers to gain access to sensitive data and systems without the need for user interaction. This vulnerability highlights the need for effective mitigation strategies, including regular updates, patching, and monitoring of AI-powered systems.

    In response to the Plugin4Shell vulnerability, the vendors affected by the vulnerability have been working to develop patches and mitigations. Anthropic and OpenAI have already patched their respective agents, while Google has deprecated its Gemini CLI and suggested that users migrate to its newer Antigravity agentic development environment. Microsoft, however, has not yet patched its Copilot, despite being one of the vendors that was notified of the vulnerability in June.

    The GitHub community has also taken steps to mitigate the Plugin4Shell vulnerability, by implementing a SHA-pinning mechanism that locks agent plugins and skills to a specific, immutable commit hash. However, the researchers caution that this mitigation is not sufficient to defeat the Plugin4Shell attacks, as marketplaces can be hosted on other platforms that do not implement this mechanism.

    In conclusion, the Plugin4Shell vulnerability is a critical threat to the security of AI-powered systems. It highlights the need for effective mitigation strategies, including regular updates, patching, and monitoring of AI-powered systems. As the use of AI and ML technologies continues to grow, it is essential to prioritize cybersecurity and develop effective countermeasures to protect against this type of vulnerability.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/A-Critical-0-Click-Vulnerability-in-AI-Coding-Agents-A-Threat-to-Cybersecurity-ehn.shtml

  • https://www.theregister.com/security/2026/09/17/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom/5297335


  • Published: Thu Sep 17 18:10:13 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us