← BLOG
Tools7 min

Plugin4Shell: The Zero-Click Bug That Broke SHA-Pinned Plugins in Claude Code, Codex, Copilot, and Gemini CLI

SolidAtoms Team
OCT 10, 2026
Plugin4Shell: The Zero-Click Bug That Broke SHA-Pinned Plugins in Claude Code, Codex, Copilot, and Gemini CLI

On September 17, 2026, security researchers at Air Security disclosed a vulnerability with a name that deliberately echoes Shellshock and Log4Shell: Plugin4Shell. It's a zero-click remote code execution bug that affects the plugin-installation flow in four of the most widely used AI coding agents — Claude Code, OpenAI's Codex, GitHub Copilot, and Gemini CLI. The bug doesn't exploit a bad password or a phishing link. It exploits something engineers were told to trust: a pinned Git commit SHA.

That's what makes it worth understanding in some depth, even if you never touch these agents' plugin systems directly. SHA pinning is the standard advice for locking a dependency to an exact, immutable version — "don't trust a branch name, trust the hash." Plugin4Shell shows that the hash alone isn't enough if nothing checks that the code you actually received matches it.

How the trick works

Each of the affected agents lets you install a plugin pinned to a specific 40-character commit hash, so an update to the plugin's repository can't silently change what gets installed. According to Air Security's writeup, the flaw is that these agents request the pinned commit — but never confirm that the working tree Git actually checks out matches that commit object.

Git allows branch and tag names that look identical to a commit hash. An attacker who controls a plugin repository can create a branch literally named after the victim's pinned 40-character SHA. During checkout, Git can resolve that ambiguous reference to the branch — attacker-controlled and mutable — instead of the immutable commit object the agent thinks it asked for. The agent then reports a successful, "verified" install of the pinned SHA, while the code that actually landed on disk is whatever the attacker put on that branch. No approval dialog, no click, no warning: the check passes and the malicious payload runs with the agent's permissions.

The bug isn't in Git. It's in the assumption that requesting a SHA and receiving code that runs are the same thing.

Who's patched, and who isn't

Patch status differs sharply across the four vendors, which is arguably the more newsworthy part of the story:

  • Anthropic patched Claude Code in version 2.1.179.

  • OpenAI patched Codex in version 0.146.0.

  • Google said Gemini CLI is deprecated and will not receive a fix, instead pointing users toward its successor, Antigravity.

  • Microsoft had not shipped a fix for GitHub Copilot as of disclosure. GitHub noted that its own platform separately blocks the creation of SHA-like branch and tag names, which mitigates the specific attack vector for repositories hosted there.

In other words: if you're on Claude Code or Codex, update now. If you're driving plugin installs through Gemini CLI or Copilot, the exposure window is still open, and "GitHub blocks it on GitHub" is not the same guarantee as "the client verifies it," since plugin sources aren't limited to GitHub-hosted repos.

Why this lands differently than a normal CVE

This disclosure arrives at an awkward moment for the coding-agent market. The same week, Anthropic rolled a coordinator and parallel cloud threads into Claude Code Projects for select Pro and Max users, SpaceX finished folding Cursor's parent company Anysphere into its new SpaceXAI division in a $60 billion deal, and Cognition merged Windsurf into Devin Desktop. Agentic coding tools are consolidating and shipping faster plugin and extension ecosystems at the same time — MCP servers, marketplace plugins, cloud agent threads that install dependencies without a human watching each step.

That combination is exactly what makes Plugin4Shell worth taking seriously beyond its immediate patch list. A zero-click RCE in a plugin-install path is bad on its own. A zero-click RCE in the plugin-install path of an autonomous agent — one that can already read your filesystem, hold API keys, and execute shell commands on your behalf — is a much shorter hop from "install a bad dependency" to "full workstation compromise." The four affected tools between them are installed on a very large share of professional developer machines, which is presumably why researchers reached for the Shellshock/Log4Shell naming convention rather than a quieter label.

What to actually do about it

  • Update Claude Code to 2.1.179+ and Codex to 0.146.0+ today if you haven't already — check your version with the CLI's own version flag rather than assuming auto-update caught it.

  • If your team relies on Gemini CLI for plugin installs, treat it as unsupported for that workflow now and plan the migration to Antigravity rather than waiting for a patch that Google has said isn't coming.

  • For Copilot, avoid installing third-party plugins from untrusted or unfamiliar repositories until Microsoft ships a fix, and prefer sources hosted on GitHub itself, where the SHA-like-ref restriction gives you an extra layer of protection.

  • More generally, don't treat "pinned to a SHA" as a security property by itself, whether you're pinning a coding-agent plugin, a GitHub Action, or a container base image. Pinning only helps if something in the chain actually verifies the checked-out content's hash matches — not just that the hash was requested.

Plugin4Shell will probably get patched everywhere within a few more weeks. The more durable lesson is about the class of bug: as coding agents get more autonomy and more plugin surface area, the gap between "we asked for the trusted version" and "we verified we got it" is exactly where the next one will show up too.


Sources