cd /news/ai-safety/plugin4shell-your-ai-coding-agents-p… · home › topics › ai-safety › article
[ARTICLE · art-142175] src=byteiota.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

Plugin4Shell: Your AI Coding Agent’s Plugin Store Is an RCE

A zero-click remote code execution vulnerability dubbed Plugin4Shell affects AI coding agents Claude Code, Codex, Copilot, and Gemini CLI through a SHA pinning bypass, according to byteiota. The report urges users to check patch status and act immediately.

read1 min views1 publishedSep 30, 2026

Plugin4Shell is a zero-click RCE hitting Claude Code, Codex, Copilot, and Gemini CLI via SHA pinning bypass. Check patch status and act now.

The post Plugin4Shell: Your AI Coding Agent’s Plugin Store Is an RCE appeared first on byteiota .

── more in #ai-safety 4 stories · sorted by recency
── more on @plugin4shell 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/plugin4shell-your-ai…] indexed:0 read:1min 2026-09-30 · —