Plugin4Shell Zero-Click RCE Vulnerability Affects Claude, Copilot, and Gemini
September 17, 2026
A high-severity zero-click remote code execution vulnerability, Plugin4Shell, affects Claude Code, Codex, Copilot, and Gemini. Attackers can silently swap trusted plugins for malicious ones, bypassing SHA pinning and inheriting the full execution permissions of the user's agent.
HOW THIS AFFECTS YOU
●
builderYou must update your agents immediately and audit third-party plugin integrations.
●
policyThis highlights critical supply-chain risks in the growing AI agent ecosystem.