cd /news/ai-agents/zero-click-rce-vulnerability-hit-fou… · home topics ai-agents article
[ARTICLE · art-133496] src=helpnetsecurity.com ↗ pub= topic=ai-agents verified=true sentiment=↓ negative

Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched

A zero-click remote code execution vulnerability affects four major AI coding agents — Claude Code, Codex, GitHub Copilot and Gemini CLI — and two of them remain unpatched, according to security researchers at AIR. AIR called it "the first supply chain vulnerability of the AI agent ecosystem," warning that anyone running a major coding agent that installs plugins from a marketplace is exposed, with an attacker gaining the same reach into company systems and data as the employee running the agent.

by read1 min views1 publishedSep 18, 2026

Four major AI coding agents, Claude Code, Codex, GitHub Copilot and Gemini CLI, all share the same zero-click RCE vulnerability, one that could give an attacker the same reach into a company’s systems and data as the employee running the agent, according to AIR. “It is the first supply chain vulnerability of the AI agent ecosystem,” the researchers said. “Anyone running a major coding agent that installs plugins from a marketplace is exposed. The exposure … More

The post Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched appeared first on Help Net Security.

── more in #ai-agents 4 stories · sorted by recency
── more on @claude code 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/zero-click-rce-vulne…] indexed:0 read:1min 2026-09-18 ·