Subscribe Sign in

AI coding agents' 0-click RCE flaw could hand attackers keys to the kingdom

1 min read Rewritten in plain language

Security

Show what we removed Rules applied: A1×4 A3 D2×2 D3×8 D4 E3×3 F2×7 all 30 rules
  • Plugin4Shell attack affects all the coding agents, researchers say.
  • Almost 90 percent of Fortune 500 companies use Copilot, according to Microsoft, which also happens to be one of the two that didn’t ship a patch for the flaw.
  • The Air team reported the security issue to all four vendors in June, and both Anthropic and OpenAI patched it in Claude Code 2.1.179 and Codex 0.146.0, respectively.
  • The Air researchers said that the GitHub mitigation isn’t enough to defeat Plugin4Shell attacks.
  • The researchers say an attacker could abuse this flaw in two ways.

5 sentences from our version of the report, chosen to cover it. Nothing here is written; every line is in the article below. How

Plugin4Shell attack affects all the coding agents, researchers say. Instead of targeting the model or agent, Plugin4Shell attacks trusted marketplaces that host plugins for coding agents.

The report’s most important sentence, shortened and in plain words. How

Headline check

The one thing this headline claims is in the report.

Figures, names and quoted words in the headline, looked for in the report itself — not in the summary above. One claim in this headline could be checked, so this is a narrow pass and not a thorough one. How this is checked

Plugin4Shell attack affects all the coding agents, researchers say.

The exploit, dubbed “Plugin4Shell,” is a “first-of-its-kind AI supply-chain attack,” according to threat hunters at Air, a security startup focused on protecting enterprise AI agents.

Instead of targeting the model or agent, Plugin4Shell attacks trusted marketplaces that host plugins for coding agents.

Almost 90 percent of Fortune 500 companies use Copilot, according to Microsoft, which also happens to be one of the two that didn’t ship a patch for the flaw.

“The fix has to ship in the agent, and updating is the only complete mitigation where one exists,” Air researchers Or Nevo, Dor Granat, and Niv Hoffman said in a Thursday report.

The Air team reported the security issue to all four vendors in June, and both Anthropic and OpenAI patched it in Claude Code 2.1.179 and Codex 0.146.0, respectively.

Google has deprecated the Gemini CLI and therefore told Air it will not patch, so every install remains vulnerable. Google does, however, suggest users migrate to its newer Antigravity agentic development environment, which is protected from this attack.

The Air researchers said that the GitHub mitigation isn’t enough to defeat Plugin4Shell attacks.

Redmond did not at once respond to The Register ’s request for comment.

Agents’ plugin auto-update feature makes this a zero-click attack. When a pinned commit is swapped upstream, the agent’s plugin gets replaced with a malicious version, and both Claude and Codex automatically update installed plugins by default.

The researchers say an attacker could abuse this flaw in two ways.

Shortened to 1 minute of reading, this version reads 6.8 on the Niral Score.

You are reading our version, not theirs. This is The Register's report shortened to its most important sentences, in plainer words, with verdicts and loaded words taken out. Plain description stays, and so do adjectives that carry a fact, such as "former" or "federal". The reporting, the facts and the quotations are theirs — quotations are never edited — and the indicators beside it measure this version. Hover or tap Adjectives to see every one left in the text.

How this outlet filed it, and how we rewrote it

No other newsroom we read has filed on this event, so there is nothing to compare it with yet.

Outlet Niral ScoreAdjectivesSourcingSentimentHappiness
The Registeras they published this story 11.1 19 74 -0.3 29.4
Mundane Readneutralized from The Register 8.7 15 74 -0.3 29.4

Sign in to react.

Comments

Nothing here yet.

Sign in to comment.

Questions

Readers can ask a question about this story here. Questions and answers are for subscribers. Sign in to read them.

Comments are read before they appear where anything in them needs a person to look. Nothing posted here is ever deleted; a comment taken down keeps its text and the reason, so the decision can be looked at again. How this works