CYBERSECURITYTRACKER
TRACKING6,994 stories in this site build1,470 vulnerability news stories in this site build
Permanent story citation

AI coding agents' 0-click RCE flaw could hand attackers keys to the kingdom

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7712

As cited

Copy frozen at (site build).

vulnerabilities

AI coding agents' 0-click RCE flaw could hand attackers keys to the kingdom

A zero-click remote code execution vulnerability called Plugin4Shell affects major artificial intelligence (AI) coding agents including Anthropic's Claude Code, OpenAI's Codex, Google's Gemini CLI, and Microsoft Copilot by exploiting how they verify plugin commits from trusted marketplaces. The flaw allows attackers to swap legitimate code with malicious payloads while maintaining the appearance of valid security pinning, potentially granting full system access to anyone whose agent downloads a compromised plugin. Anthropic and OpenAI have patched their tools, but Google deprecated Gemini CLI without patching, and Microsoft has not yet released a fix for Copilot despite six months of disclosure.

Why it matters: Organizations deploying artificial intelligence (AI) coding agents across developer teams face immediate remote code execution risk if they run unpatched versions; approximately 90 percent of Fortune 500 companies use GitHub Copilot, which remains vulnerable on non-GitHub marketplace platforms like Bitbucket where the attack succeeds.

VendorsMicrosoftGoogleAtlassianGitHub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary