Redbot Labs / Threat Intelligence
Plugin4Shell Bypasses Plugin Version Pinning Across Four AI Coding Agents
- Incident ID
- RBT-TI-0101
- Organization
- Anthropic / OpenAI / GitHub / Google
- Reported Location
- United States - Multi-Vendor Country-Level Reference; No Victim Location Disclosed
- Severity
- High
- Category
- AI Agent Supply Chain / Plugin Integrity Bypass / Remote Code Execution
- Record Date
- 2026-09-17
Incident Summary
Plugin integrity failure. AIR Security demonstrated Plugin4Shell, a vulnerability allowing attacker-controlled repository content to replace a plugin’s reviewed, pinned version.
Affected agents. The research covered Claude Code, Codex, GitHub Copilot, and Gemini CLI.
What Happened
Repository control required. An attacker controlling a plugin repository could exploit ambiguous Git references to make an installation resolve to unintended code.
Missing verification. Affected clients failed to confirm that the checked-out commit matched the expected pin.
Background exposure. Automatic plugin updates could trigger the substitution without additional user interaction.
Reported fixes. AIR identified Claude Code 2.1.179 and Codex 0.146.0 as patched versions.
Affected Systems
AI Coding Agent Plugin Installation / Plugin Auto-Updates / Git Repository Resolution
Attack Vector
Attacker-Controlled Plugin Repository / Commit-Pinning Bypass / Malicious Plugin Execution
Business Impact
Potential host compromise. Malicious plugin code could execute with the access available to the coding agent.
Evidence limits. The disclosure presents working demonstrations, without establishing a breached-customer count or confirmed losses.
Technical findings and version details are attributed to AIR Security’s disclosure.
Redbot Analysis
Review must match the code that executes. Redbot Labs assesses that plugin approval depends on verifying the installed artifact, not merely recording an approved version identifier. A mismatch breaks the connection between security review and runtime behavior.
Treat updates as security-sensitive changes. Background updates should preserve integrity guarantees and produce auditable records of the expected and installed versions. A failed integrity check should stop installation.
Reduce plugin authority. Coding agents should receive only the repository, credential, and network access necessary for their work. This limits the consequences if an approved dependency becomes malicious.
Validate the distribution path. Testing should cover repository ownership changes, reference ambiguity, update behavior, and installation failures alongside the plugin’s own functionality.

