Plugin4Shell: Can a Pinned AI Agent Plugin Still Turn Into a Zero-Click Backdoor?

September 30, 2026

Plugin4Shell reportedly let Claude Code, Codex, Copilot, and Gemini CLI install code other than the reviewed commit. Here is what is confirmed, patched, and still unclear.

Research cutoff: September 30, 2026. This article analyzes AIR Security's Plugin4Shell disclosure, public vendor release evidence, and current independent coverage. It does not establish that the flaw was exploited against real users.

Yes, a supposedly pinned AI-agent plugin could reportedly resolve to different, attacker-controlled code. The Plugin4Shell disclosure says Claude Code, OpenAI Codex, GitHub Copilot, and Gemini CLI all failed to verify the commit that actually landed after Git checkout. With an already-installed plugin and automatic updates, that gap could turn a repository takeover or deliberate rug-pull into code execution without another click.

The headline needs two important limits. The attacker first needs control of a plugin's source repository, and the main branch-name technique depends on a Git host that permits a branch shaped like a 40-character commit hash. This is not evidence that any random prompt can compromise those tools. It is also not evidence of exploitation in the wild.

Anthropic and OpenAI shipped fixes. AIR identifies Claude Code 2.1.179 and Codex 0.146.0 as the patched versions. The public Codex 0.146.0 release includes a changelog item named “Verify Git plugin SHA checkouts.” The picture for GitHub Copilot and the retired Gemini CLI was less straightforward at the disclosure cutoff.

What Is Plugin4Shell?

Plugin4Shell is a plugin-supply-chain vulnerability disclosed by AIR Security on September 17, 2026. It targets a trust promise that sounds simple: if a marketplace pins a plugin to a reviewed Git commit, the agent should install exactly that commit.

According to AIR, all four tested coding agents requested the pinned commit but failed to perform the final identity check that mattered: resolving the checked-out working tree's HEAD and comparing it with the expected commit hash.

That difference between requesting a pin and verifying the result is the whole story.

A Git commit hash is designed to identify immutable content. But a command such as git checkout <value> still has to interpret the value. If an attacker-controlled repository can create a branch with the same 40-hex-character name as the pinned commit and make it the default branch, Git can resolve the ambiguous name to the branch. The agent may believe it honored the pin even though the working tree contains code from somewhere else.

AIR describes a different variant for Gemini CLI. Its flow fetched the intended commit and then checked out FETCH_HEAD. A malicious default branch named FETCH_HEAD could reportedly make that checkout land on the branch instead of the fetched commit.

In both cases, one post-checkout assertion would expose the mismatch:

resolved HEAD == expected pinned commit

If the values differ, installation or update should stop before plugin discovery, dependency installation, or execution.

What Is Confirmed

AIR published a working proof of concept against four agent families

AIR says it found the issue in May 2026, demonstrated working proof-of-concept paths against Claude Code, Codex, GitHub Copilot, and Gemini CLI, and privately disclosed the findings to the four vendors in June.

The primary disclosure documents two reference-resolution techniques and the conditions required for each. The Cloud Security Alliance analysis independently explains the same missing post-checkout verification step and maps the reported patch status.

The attacker must control or compromise the plugin repository

Plugin4Shell is not a drive-by attack against every coding-agent session. AIR's demonstrated chain begins only after an attacker can change the repository behind a marketplace plugin.

That can happen in two broad ways:

  1. An attacker publishes a benign plugin, earns review and adoption, and later turns the repository malicious.
  2. An attacker compromises or takes over a repository that already backs a trusted plugin.

The vulnerability matters because pinning is supposed to contain exactly that upstream change. If the client never verifies what actually landed on disk, the control can fail at the final step.

Automatic updates can remove the last visible user action

AIR says Claude Code and Codex enabled automatic plugin updates by default in the affected flows. If a marketplace approved a routine version bump and the attacker then prepared the ambiguous repository state, an installed plugin could update to substituted code without a new install prompt.

That is why “zero-click” is defensible here. It does not mean the attacker needs no setup. It means the victim may not need to click or approve anything at the moment the malicious update reaches an already-installed plugin.

Claude Code and Codex have patched releases

AIR lists these fixed versions:

Anthropic's public Claude Code 2.1.179 release establishes that the version shipped in June. Its visible summary does not call out Plugin4Shell by name, so the security attribution comes from AIR's coordinated-disclosure timeline.

OpenAI's public Codex 0.146.0 release is more explicit: its full changelog names the fix as “Verify Git plugin SHA checkouts.” AIR says it verified the Codex remediation on August 12.

GitHub disputes the broadest Copilot framing

A GitHub spokesperson told The Register that GitHub does not permit branch or tag names resembling commit hashes, so AIR's branch-name technique cannot be exploited against plugins hosted on GitHub.

AIR's response is narrower than “GitHub is wrong.” It argues that Copilot supports marketplaces hosted elsewhere, including environments where commit-shaped branch names may be allowed. The host restriction can therefore block one path without proving that every supported plugin origin is safe.

Google did not patch the tested Gemini CLI path

AIR says Google deprecated the affected Gemini CLI plugin path and advised migration to Antigravity rather than shipping a fix. AIR also says the tested Antigravity architecture does not use the same marketplace SHA-pinning path.

That is a statement about this specific exploit. It does not prove that Antigravity is immune to all plugin, extension, supply-chain, or prompt-injection risks.

What Is Still Unclear

There is no published evidence of exploitation in the wild

AIR demonstrated the chain in research. Neither AIR nor the independent sources reviewed for this article identified a real victim compromised through Plugin4Shell.

Proof that an attack is possible is not proof that it happened. Treat this as a patch-and-audit event, not as confirmation that credentials or source code were stolen from known organizations.

Plugin4Shell still has no verified CVE attribution

AIR and Cloud Security Alliance reported no CVE identifier for Plugin4Shell when the research became public. A third-party threat page now attributes Plugin4Shell to CVE-2026-76460 and claims active exploitation, but the official GitHub Advisory Database record assigns that CVE to a Cisco Identity Services Engine authentication bypass, not to Plugin4Shell.

No authoritative source reviewed through September 30 tied a CVE or in-the-wild exploitation to Plugin4Shell. That does not make the vulnerability unreal, but it means defenders should not repeat the conflicting CVE or exploitation claim and cannot rely on a CVE-only inventory to find affected installations.

The true exposed population is not public

AIR uses broad language about major coding agents and millions of agents, but the number of installations meeting every prerequisite is not established publicly.

Exposure depends on details such as:

Earlier AIR research figures about skill adoption and repository takeover are evidence that upstream trust failures are plausible. They are not counts of Plugin4Shell victims.

Copilot's status depends on the complete supported-origin boundary

GitHub's branch-name restriction is strong contrary evidence for GitHub-hosted repositories. The unresolved question is whether every Copilot marketplace origin is constrained by the same rule or whether supported Bitbucket and self-hosted origins leave the client-side gap relevant.

Until Microsoft or GitHub publishes a complete affected-origin matrix or a client verification change, teams should avoid reducing the conclusion to either “all Copilot users are vulnerable” or “Copilot is universally unaffected.”

Public documentation does not answer every forensic question

The sources reviewed do not publish a universal artifact, log entry, or command that proves a particular machine was never served substituted code before patching. An inventory can find installed versions and origins, but incident review may also need endpoint telemetry, repository audit history, resolved commit records, process execution logs, and credential-use evidence.

Why A Pinned Commit Was Not Enough

Pinning protects identity only when every layer agrees on what the identity means.

Consider the intended chain:

  1. A marketplace reviews plugin code.
  2. The marketplace records the reviewed commit hash.
  3. The agent asks Git for that commit.
  4. Git materializes a working tree.
  5. The agent loads or executes the plugin.

Plugin4Shell reportedly breaks the chain between steps 3 and 4. The marketplace can store the right hash. The client can request the right text. But if Git resolves that text to a different object and the client never compares the final HEAD, the later execution step receives code that was not the reviewed artifact.

This is a useful lesson beyond AI agents: a requested identifier is not proof of a resolved artifact. The same principle applies to container tags versus digests, package lockfiles versus downloaded bytes, signed releases versus extracted directories, and model names versus exact weight files.

Why Coding-Agent Plugins Have A Large Blast Radius

A plugin is not merely extra text for a model. Depending on the agent, it can contribute tools, commands, hooks, skills, configuration, dependencies, or code that runs in the developer's environment.

That environment may contain:

The exact blast radius is the authority of the process and user account running the agent. Plugin4Shell does not magically grant administrator rights or access that the host does not have. But a developer workstation often has enough ambient authority to make ordinary user-level code execution serious.

This is why the risk is not solved by asking whether the underlying language model is safe. The failure lives in the client, plugin distribution, Git resolution, update policy, and host-permission layers around the model.

What Developers Should Do Now: The PINNED Check

Use PINNED as a practical response sequence.

P — Patch every affected client

Confirm Claude Code is at least 2.1.179 and Codex is at least 0.146.0. Do not assume an auto-updater succeeded; record the version from the actual binary or managed installation on each workstation and CI runner.

For Copilot plugin use, follow current Microsoft and GitHub guidance and evaluate non-GitHub origins separately. Retire the affected Gemini CLI plugin path rather than assuming deprecation itself removes old installations.

I — Inventory installed plugins and their origins

Build a list of every agent, plugin, marketplace, repository URL, pinned commit, installed version, update mode, and host. Pay special attention to Bitbucket and self-hosted Git origins, but do not treat a familiar host as a substitute for client-side verification.

N — Note the resolved commit, not only the requested pin

For each installed plugin, independently resolve the checked-out HEAD and compare it with the approved commit. Preserve the result with a timestamp and the repository origin used.

A UI badge or manifest saying “pinned” is not enough. The artifact on disk is what will run.

N — Narrow automatic updates when verification is unavailable

Disabling automatic updates can remove the zero-click delivery step on an unpatched client. It is a temporary mitigation, not a complete fix. It will not clean a plugin that was already substituted, and manual installation can still execute malicious code.

E — Enforce least privilege around the agent

Run coding agents and extensions with only the filesystem, credentials, network destinations, and deployment authority needed for the task. Separate personal browsing, production administration, and high-value signing credentials from extension-heavy development environments.

Containment does not repair the pinning bug, but it reduces what a compromised plugin can reach.

D — Detect signs of prior substitution

Review repository ownership changes, default-branch changes, unusual commit-shaped branch names, plugin update records, child processes, outbound connections, credential use, and unexpected file changes. Rotate exposed secrets when evidence justifies it; do not rotate blindly without first preserving the records needed to understand scope.

What Plugin Marketplaces And Agent Vendors Should Change

The durable client control is simple to describe even if safe implementation needs care:

  1. Fetch the intended commit using an unambiguous object path.
  2. Check out the object without trusting a branch-like name.
  3. Resolve the resulting HEAD locally.
  4. Compare it byte-for-byte with the approved commit hash.
  5. Abort before loading any manifest, dependency, hook, or executable content if the comparison fails.
  6. Record the origin, expected commit, resolved commit, signer or review state, and update event in an audit log.

Marketplaces should also treat repository ownership and origin changes as high-risk events, require re-review for material plugin changes, and publish clear revocation behavior. Vendors should document whether plugins run inside a sandbox, which permissions they inherit, how users can freeze or disable updates, and how defenders can inspect installed state.

What This Does Not Prove

Plugin4Shell does not prove that:

The flaw is in the software-supply-chain machinery surrounding agent extensions. A locally running agent may keep more work on hardware you control, but local execution also puts plugin code close to local files, credentials, and developer tools. A hosted service has different processing and trust boundaries. Neither architecture is private merely because of one label.

For a broader architecture comparison, see Private AI Chat vs Local AI. For upload-specific boundaries, see Private AI With File Uploads: What Still Gets Processed.

Where OpenVeil Fits — And Where It Does Not

OpenVeil is not a coding agent, plugin marketplace, Git verifier, software sandbox, endpoint-security product, or Plugin4Shell patch. It does not protect another application from malicious extensions or unrelated repository compromise.

The relevant choice is narrower. Some users do not need an autonomous coding agent with marketplace plugins, shell execution, repository access, and deployment credentials for every AI task. When the job is private brainstorming, writing, research, search, file-assisted conversation, voice, images, video, or custom personas, a smaller authority boundary can be easier to reason about.

OpenVeil is an 18+ hosted, privacy-focused AI workspace. Normal chat history stays in the browser, and OpenVeil does not keep a normal server-side chat-history record. OpenVeil also does not use documented prompts, uploads, media, selected local history, or outputs to train foundation models. Active requests still require processing by OpenVeil and necessary providers, and the service is not anonymous, fully offline, zero-log, or a defense against malware on your device.

If that narrower workflow matches the task, you can try OpenVeil's ten-action preview without a card. If code execution, local models, or autonomous tools are required, evaluate those capabilities with their own plugin, permission, logging, and supply-chain controls.

Frequently Asked Questions

Is Plugin4Shell really zero-click?

It can be zero-click at the delivery stage when a vulnerable client automatically updates an already-installed plugin. The attacker still needs control of the plugin repository and must prepare the repository state that triggers the pinning bypass.

Was OpenAI Codex patched?

Yes. AIR says Codex 0.146.0 fixes the issue, and OpenAI's release changelog includes “Verify Git plugin SHA checkouts.” Users should confirm the version of the binary they actually run.

Was Claude Code patched?

AIR says Claude Code 2.1.179 fixes the issue. The public release establishes that version's availability, while AIR's disclosure supplies the coordinated-security attribution.

Is GitHub Copilot affected?

The answer depends on repository origin. GitHub says its own hosting blocks branch names that resemble commit hashes, preventing AIR's primary branch-name technique there. AIR says Copilot also supports other marketplace origins where that restriction may not exist. A universal claim in either direction would be stronger than the public evidence.

Is Gemini CLI still vulnerable?

AIR says Google did not patch the deprecated Gemini CLI path and advised users to migrate to Antigravity. Old local installations do not disappear merely because a product is deprecated, so teams should inventory and retire them deliberately.

Does disabling plugin auto-update solve the problem?

It removes the automatic, no-click update path but does not fix checkout verification. It also does not prove that an installed plugin was never substituted before auto-update was disabled.

Does Plugin4Shell affect ordinary AI chat?

Not by itself. The disclosed flaw concerns coding-agent plugin installation and update paths. An ordinary chat product without that plugin mechanism is not affected by this specific vulnerability, though it has other privacy and security boundaries.

Bottom Line

Plugin4Shell shows why “pinned” is a claim that must be verified at the last responsible moment. Claude Code, Codex, GitHub Copilot, and Gemini CLI reportedly requested reviewed plugin commits but did not always verify the commit that actually landed on disk. Under the required repository-control conditions, automatic updates could turn that gap into zero-click code execution.

Patch Claude Code and Codex, retire the affected Gemini CLI path, treat Copilot's non-GitHub plugin origins as a separate boundary, inventory installed extensions, compare resolved HEAD values with approved commits, and reduce the authority available to every plugin. Do not convert a proof of concept into a claim of real-world compromise—but do not wait for a public victim before fixing a broken integrity check.

Sources

When privacy, account control, uploads, and search matter, OpenVeil gives you a private AI workspace designed for that job.