Four major AI coding agents, Claude Code, Codex, GitHub Copilot and Gemini CLI, all share the same zero-click RCE vulnerability, one that could give an attacker the same reach into a company’s systems and data as the employee running the agent, according to AIR. “It is the first supply chain vulnerability of the AI agent ecosystem,” the researchers said. “Anyone running a major coding agent that installs plugins from a marketplace is exposed.
Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched
About this summary. This is a short, independently written summary of an article first published by Help Net Security. Cyber Security News did not report or verify the underlying story. Read the original: https://www.helpnetsecurity.com/2026/09/18/plugin4shell-ai-coding-agents-vulnerability/

Source attribution: headline and facts are from Help Net Security (helpnetsecurity.com). Summary method: excerpt of the source description. See our source attribution policy and corrections policy.






