ACVEAgent configuration vulnerability registry

ACVE-2026-0444

Changed plugin code could be installed under a reviewed, pinned marketplace plugin revision and run with the user's privileges in Claude Code, Codex, GitHub Copilot and Gemini CLI.

Exposure

Reproducibility: partial (vulnerable components are not confirmed obtainable; trigger not published)

Claims

Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.

Claims on this page have not been checked against primary sources.

In the wild

weaponised-poc · research

Description

What

AIR's Plugin4Shell disclosure described a supply-chain defect shared by four coding agents: plugin pinning did not reliably ensure that the installed code matched the reviewed revision. A malicious plugin could then run with the same access as the agent, including access to files, credentials and connected systems.

Detection

AIR demonstrated proof-of-concept exploits against all four agents; the report is not a lab recreation by this registry.

Fix

Upgrade Claude Code to 2.1.179 and Codex to 0.146.0; GitHub Copilot remained unpatched in the report, and Google said Gemini CLI would not be fixed because it was being retired.

Fix

Upgrade patched agents and remove plugins from unpatched agents until their pinning is fixed.

  • Upgrade harness:claude-code to 2.1.179. Version stated by the report. Owner: operator
  • Upgrade harness:codex-cli to 0.146.0. Version stated by the report. Owner: operator

References

REPORT

Report a problemJSON