Redbot Labs / Threat Intelligence

Plugin4Shell Bypasses Plugin Version Pinning Across Four AI Coding Agents

Incident ID
RBT-TI-0101
Organization
Anthropic / OpenAI / GitHub / Google
Reported Location
United States - Multi-Vendor Country-Level Reference; No Victim Location Disclosed
Severity
High
Category
AI Agent Supply Chain / Plugin Integrity Bypass / Remote Code Execution
Record Date
2026-09-17

Incident Summary

Plugin integrity failure. AIR Security demonstrated Plugin4Shell, a vulnerability allowing attacker-controlled repository content to replace a plugin’s reviewed, pinned version.

Affected agents. The research covered Claude Code, Codex, GitHub Copilot, and Gemini CLI.

What Happened

Repository control required. An attacker controlling a plugin repository could exploit ambiguous Git references to make an installation resolve to unintended code.

Missing verification. Affected clients failed to confirm that the checked-out commit matched the expected pin.

Background exposure. Automatic plugin updates could trigger the substitution without additional user interaction.

Reported fixes. AIR identified Claude Code 2.1.179 and Codex 0.146.0 as patched versions.

Affected Systems

AI Coding Agent Plugin Installation / Plugin Auto-Updates / Git Repository Resolution

Attack Vector

Attacker-Controlled Plugin Repository / Commit-Pinning Bypass / Malicious Plugin Execution

Business Impact

Potential host compromise. Malicious plugin code could execute with the access available to the coding agent.

Evidence limits. The disclosure presents working demonstrations, without establishing a breached-customer count or confirmed losses.

Technical findings and version details are attributed to AIR Security’s disclosure.

Redbot Analysis

Review must match the code that executes. Redbot Labs assesses that plugin approval depends on verifying the installed artifact, not merely recording an approved version identifier. A mismatch breaks the connection between security review and runtime behavior.

Treat updates as security-sensitive changes. Background updates should preserve integrity guarantees and produce auditable records of the expected and installed versions. A failed integrity check should stop installation.

Reduce plugin authority. Coding agents should receive only the repository, credential, and network access necessary for their work. This limits the consequences if an approved dependency becomes malicious.

Validate the distribution path. Testing should cover repository ownership changes, reference ambiguity, update behavior, and installation failures alongside the plugin’s own functionality.

Sources

Related Attack Intelligence