· 9 min read

Plugin4Shell Broke SHA Pinning in Four AI Coding Agents. Two Are Still Unpatched.

A vulnerability called Plugin4Shell lets an attacker who controls a plugin's repository swap in malicious code while every signal on your machine says the plugin is still pinned to the reviewed commit you trusted. It hits all four major AI coding agents: Claude Code, Codex, GitHub Copilot, and Gemini CLI. It takes zero clicks, because if you already have the plugin installed and background auto-update on (the default in Claude Code and Codex), the swap just happens. Security firm Air Security disclosed it publicly on September 17, 2026. As of this week, two of the four vendors have shipped a fix, one has declined to, and one hasn't responded at all.

what SHA pinning was supposed to guarantee

Plugin marketplaces pin an installed plugin to a specific 40-character commit hash after someone reviews it, the idea being that the code cannot change underneath you without your knowledge. Air Security's own writeup puts the actual bug plainly: the agent checks out the exact commit the marketplace pinned but never verifies it landed there, so an attacker who controls the plugin's repo can make the checkout resolve to malicious code while the pin still looks honored.

There are two ways this plays out depending on the agent. In Claude Code, Codex, and GitHub Copilot, the attacker creates a git branch named exactly like the pinned 40-hex commit hash and sets it as the repository's default. Git prefers a ref over a commit object with the same name, so a plain checkout resolves to the malicious branch instead of the pinned commit, and nothing about the install looks wrong. Gemini CLI has a separate variant: it fetches the correct commit into FETCH_HEAD and then runs git checkout FETCH_HEAD, and if the attacker names their default branch FETCH_HEAD, that checkout resolves to the branch instead of the fetched commit. Different mechanism, same outcome. The fix in both cases is one missing assertion: after checkout, confirm the working tree's actual HEAD matches the pinned hash, and abort if it doesn't. None of the affected agents did that.

found in may, disclosed in june, public in september

Air Security says it found the bug in May 2026 with a working proof of concept against all four agents, then disclosed it to Anthropic, OpenAI, Google, and Microsoft in June 2026. Public disclosure landed September 17, roughly the industry's usual three-month runway between private notice and going public. Anthropic confirmed a fix within weeks of disclosure; OpenAI's fix was confirmed in August. Google and Microsoft took the disclosure window in very different directions, which is really the second half of this story.

patch status is messier than four checkboxes

Anthropic patched Claude Code in version 2.1.179. OpenAI patched Codex in version 0.146.0. Both are simple version bumps, and if you haven't updated in a while, that alone is worth five minutes today.

Google chose not to patch Gemini CLI at all. Instead it's deprecating the tool and telling users to move to Antigravity, which doesn't use this plugin SHA-pinning system and so isn't exposed to this particular bug. That's a forced migration wearing the clothes of a security advisory, and if you're still on Gemini CLI, the deprecation notice is the more urgent document.

Copilot is the genuinely unresolved one, and it's more tangled than a simple "unpatched" label suggests. A GitHub spokesperson told The Register that Plugin4Shell doesn't affect GitHub, because GitHub rejects branch names that look like commit hashes, closing off the exact trick used against Claude Code, Codex, and Copilot. Air Security disputes that this settles anything: Copilot also supports plugin marketplaces hosted on Bitbucket and self-hosted git servers, which do allow hash-shaped branch names, so the bypass still works through those paths. Microsoft has reportedly had the report since June and, according to Air, hasn't responded, which the researchers attribute to disclosure volume rather than dismissal. Either way, no patch has shipped for Copilot as of this writing.

why this lands harder when you're the only reviewer

In a team, someone usually has to sign off before a new plugin gets installed org-wide, and there's at least a chance credentials are scoped down per project. Running solo, the agent on your laptop typically has the same access you do: SSH keys, cloud provider credentials, whatever repos you've cloned, and often a path straight to production. A plugin swap that happens silently on auto-update doesn't need to trick you into anything, because you already decided to trust it once, months ago, and never thought about it again.

I checked my own setup this week mostly out of self-interest: claude --version and codex --version on the machine I use daily, both already past the patched builds. That took under a minute and told me nothing about the plugins themselves, which is the part I hadn't actually audited before this story.

what I'd actually do

Run the version checks today, not this weekend:

claude --version
codex --version

If you're below 2.1.179 on Claude Code or 0.146.0 on Codex, update now, that closes the door completely for those two. If you're on Gemini CLI, don't wait for Google to change its mind: plan the Antigravity migration on your own timeline instead of an emergency one. If you're on Copilot and any of your plugins come from a marketplace that isn't strictly GitHub-hosted, assume you're exposed until Microsoft says otherwise, because right now nobody credible is claiming a fix exists.

The bigger habit change, and the one I'm actually going to keep, is going through my installed plugins and skills and asking what each one can reach if it turned hostile tomorrow. Most of us installed these on trust and never revisited that decision. Where I think this take could be overblown: if you don't run third-party plugins or skills at all, and you're just using these agents against your own code with nothing installed from a marketplace, Plugin4Shell doesn't touch you, full stop. This is a supply chain problem, not a problem with the agents' core code generation. But the moment you add a plugin, you've extended trust to a repository you don't control, and this disclosure is proof that "it's pinned, so it's safe" was never as true as the tooling implied.

Author

Sources

Stay in the Loop

Get new posts delivered to your inbox. No spam, unsubscribe anytime.

Newsletter coming soon. Set PUBLIC_CONVERTKIT_FORM_ID in .env to activate.

Related Posts