Plugin4Shell: one git trick beat pin-locks on four AI coding agents — Microsoft unpatched
Air Security disclosed Plugin4Shell: a design flaw in how four major AI coding agents — Anthropic’s Claude Code, OpenAI’s Codex, GitHub Copilot, and Google’s Gemini CLI — pin marketplace plugins to a reviewed commit hash, so a repository owner can swap what the agent installs without the user clicking. Per The Next Web and The Hacker News, Anthropic fixed it in Claude Code 2.1.179 and OpenAI in Codex 0.146.0; Microsoft has shipped no Copilot patch, and Google says it will not fix Gemini CLI as it retires the product. High-level only: agents request the pinned snapshot but do not verify that the checked-out code matches the pin; no exploit steps or payloads here. This is the Plugin4Shell / SHA-pinning case from TNW and THN, not Air’s earlier skill-marketplace tests, not Unit 42’s enterprise intrusion, and not Cursor.