ACVE-2026-0444
Changed plugin code could be installed under a reviewed, pinned marketplace plugin revision and run with the user's privileges in Claude Code, Codex, GitHub Copilot and Gemini CLI.
Exposure
Reproducibility: partial (vulnerable components are not confirmed obtainable; trigger not published)
Claims
Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.
Claims on this page have not been checked against primary sources.
In the wild
weaponised-poc · research
Description
What
AIR's Plugin4Shell disclosure described a supply-chain defect shared by four coding agents: plugin pinning did not reliably ensure that the installed code matched the reviewed revision. A malicious plugin could then run with the same access as the agent, including access to files, credentials and connected systems.
Detection
AIR demonstrated proof-of-concept exploits against all four agents; the report is not a lab recreation by this registry.
Fix
Upgrade Claude Code to 2.1.179 and Codex to 0.146.0; GitHub Copilot remained unpatched in the report, and Google said Gemini CLI would not be fixed because it was being retired.
Fix
Upgrade patched agents and remove plugins from unpatched agents until their pinning is fixed.
- Upgrade
harness:claude-codeto2.1.179. Version stated by the report. Owner: operator - Upgrade
harness:codex-clito0.146.0. Version stated by the report. Owner: operator