Security News

Zero-Click Flaw Puts AI Coding Agents at Risk of Full Takeover

The Register · 18 Sept 2026
Key Takeaway Businesses using AI coding assistants should confirm they are running the latest patched versions, avoid Gemini CLI, and treat third-party plugin marketplaces as a potential attack surface requiring careful vetting.

Security researchers at Air have discovered a zero-click remote code execution vulnerability affecting all major AI coding agents, including Anthropic's Claude Code, OpenAI's Codex, Google's Gemini CLI, and Microsoft's Copilot and GitHub Copilot. Dubbed 'Plugin4Shell,' the flaw does not target the AI models themselves but instead exploits trusted marketplaces that host plugins for these coding tools, potentially giving attackers access to every asset and piece of data the compromised agent can reach.

The researchers describe it as a 'first-of-its-kind AI supply-chain attack' that could reach millions of users and machines given how widely these tools are used, including by nearly 90 percent of Fortune 500 companies through Copilot. Anthropic and OpenAI have patched the issue in Claude Code 2.1.179 and Codex 0.146.0 respectively. Google has deprecated Gemini CLI and will not patch it, instead recommending users move to its newer Antigravity platform. Microsoft has not issued a fix for Copilot, and while GitHub says its own mitigation prevents exploitation on its platform, researchers say Copilot remains vulnerable because it also supports marketplaces hosted on other platforms such as Bitbucket.

Air reported the vulnerability to all four vendors in June, but says it has not received a response from Microsoft regarding Copilot's continued exposure.

AI security zero-click vulnerability supply chain attack
Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from The Register. We link back to every original so you can read it yourself.