A zero-click RCE flaw in AI coding agents could have exposed enterprise systems

Summary

Researchers have discovered a zero-click remote code execution flaw, dubbed Plugin4Shell, affecting popular AI coding agents like OpenAI's Codex, Anthropic's Claude Code, Google's Gemini CLI, and GitHub Copilot. The vulnerability allows attackers to swap a trusted plugin with a malicious one, potentially gaining access to enterprise development environments without user interaction.

IFF Assessment

FOE

This vulnerability allows attackers to execute malicious code on enterprise systems, posing a significant risk to defenders.

Severity

9.0 Critical (AI Estimated)

This vulnerability allows for remote code execution without user interaction (Attack Vector: Network, User Interaction: None) and could lead to complete compromise of systems (Impact: High). The exploitability is high due to the nature of plugin interaction in AI coding agents.

Defender Context

Defenders need to be aware of emerging vulnerabilities in AI coding assistants and ensure that all plugins and associated code repositories are thoroughly vetted and kept up-to-date. This highlights the growing attack surface introduced by AI tools in development environments and the need for robust security controls around their usage.

Read Full Story →