Security/press release/2026-09-17

Zero-Click RCE Vulnerability "Plugin4Shell" Discovered in Four Major AI Coding Tools

Multiple outlets report on the discovery of "Plugin4Shell," a critical zero-click Remote Code Execution (RCE) vulnerability. This flaw reportedly affects four prominent AI coding agents: Claude Code, Codex, Copilot, and Gemini CLI. The vulnerability allowed for silent takeover of these agents by bypassing SHA-pinning mechanisms. While the specific source of the disclosure isn't detailed across all articles, the widespread reporting suggests a formal announcement or security bulletin. The consensus is that the flaw posed a significant security risk to users of these AI development tools.

6 articles from 5 outlets covered this story. No difference in framing or figures was found between them. The underlying claim is sourced from a press release.

What do all outlets agree on?

5 outlets covered “Zero-Click RCE Vulnerability "Plugin4Shell" Discovered in Four Major AI Coding Tools”. All of them report the following:

  • Vulnerability named "Plugin4Shell"
  • Zero-click Remote Code Execution (RCE) flaw
  • Affected four AI coding agents: Claude Code, Codex, Copilot, Gemini CLI
  • Allowed silent takeover
  • Bypassed SHA-pinning

Did outlets disagree about this?

No. All 5 outlets covering “Zero-Click RCE Vulnerability "Plugin4Shell" Discovered in Four Major AI Coding Tools” reported it the same way — no difference in framing or figures was found between them.

Which outlets covered this?

All 6 articles found on this story, grouped by the stance of the piece. Every link goes to the original publisher.

What related stories are there?

Which companies does this involve?

Get the week in AI in one email

What happened, which outlets reported it, and where their coverage differed. One issue a week.

The first issue hasn’t gone out yet. Subscribe and it’s the one you’ll get.

We’ll send the digest and nothing else. One-click unsubscribe. Privacy.