A zero-click RCE flaw in AI coding agents could have exposed enterprise systems
Brief
Popular AI coding agents such as OpenAI’s Codex, Anthropic’s Claude Code, Google’s Gemini CLI, and Microsoft-owned GitHub Copilot were vulnerable to a zero-click attack that enabled attackers to execute malicious code, even without developer interaction, by swapping a trusted plugin from an online marketplace for a malicious one, potentially giving them a foothold in enterprise development environments.
Researchers at cybersecurity startup AIR found and reported the flaw, which they are calling Plugin4Shell , to the vendors concerned, and most of them have now released a patch for it, the researchers wrote in a blog post on Thursday.
