
Plugin4Shell Zero-Click RCE Hits Claude Code, Codex, Copilot and Gemini CLI
Plugin4Shell is a high-severity, zero-click remote code execution vulnerability affecting major AI coding agents, including Anthropic Claude Code, OpenAI Codex, GitHub Copilot, and Google Gemini CLI. The flaw allows a malicious plugin update to execute attacker-controlled code without requiring a user to click, approve, or reinstall anything. Plugin4Shell targets the software supply chain behind AI […]
The post Plugin4Shell Zero-Click RCE Hits Claude Code, Codex, Copilot and Gemini CLI appeared first on Cyber Security News.