Plugin4Shell: Your AI Coding Agent’s Plugin Store Is an RCE A zero-click remote code execution vulnerability dubbed Plugin4Shell affects AI coding agents Claude Code, Codex, Copilot, and Gemini CLI through a SHA pinning bypass, according to byteiota. The report urges users to check patch status and act immediately. Plugin4Shell is a zero-click RCE hitting Claude Code, Codex, Copilot, and Gemini CLI via SHA pinning bypass. Check patch status and act now. The post Plugin4Shell: Your AI Coding Agent’s Plugin Store Is an RCE appeared first on byteiota .