Plugin4Shell Zero-Click Supply-Chain Flaw Threatens Multiple AI Coding Agents
Plugin4Shell affects four AI coding agents through malicious project content or workflows, with a SHA-pinning/FETCH_HEAD verification bypass enabling code execution and credential exposure without conventional user interaction. The report includes affected versions, disclosure timing, and vendor responses; production exploitation is unconfirmed, GitHub's mitigation remains disputed, and two tools reportedly remain unpatched, including a deprecated Gemini CLI.
Sources (2)
Updated Sep 18, 2026