Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched A zero-click remote code execution vulnerability affects four major AI coding agents — Claude Code, Codex, GitHub Copilot and Gemini CLI — and two of them remain unpatched, according to security researchers at AIR. AIR called it "the first supply chain vulnerability of the AI agent ecosystem," warning that anyone running a major coding agent that installs plugins from a marketplace is exposed, with an attacker gaining the same reach into company systems and data as the employee running the agent. Four major AI coding agents, Claude Code, Codex, GitHub Copilot and Gemini CLI, all share the same zero-click RCE vulnerability, one that could give an attacker the same reach into a company’s systems and data as the employee running the agent, according to AIR. “It is the first supply chain vulnerability of the AI agent ecosystem,” the researchers said. “Anyone running a major coding agent that installs plugins from a marketplace is exposed. The exposure … More https://www.helpnetsecurity.com/2026/09/18/plugin4shell-ai-coding-agents-vulnerability/ The post Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched https://www.helpnetsecurity.com/2026/09/18/plugin4shell-ai-coding-agents-vulnerability/ appeared first on Help Net Security https://www.helpnetsecurity.com .